[2024年03月]更新の300-710日本語問題集本日限定!無料アクセス可能に!Fast2testで試そう [Q118-Q140]

Share

[2024年03月]更新の300-710日本語問題集本日限定!無料アクセス可能に!Fast2testで試そう

学習材料は有効300-710日本語効率的問題集!

質問 # 118
同じサブネットのレイヤ 2 とレイヤ 3 でトラフィックを転送できるファイアウォール設計はどれですか?

  • A. 透過モード
  • B. ルーティングとブリッジングの統合
  • C. Cisco Firepower Threat Defense モード
  • D. ルーテッド モード

正解:B

解説:
Integrated routing and bridging (IRB) is a feature of Cisco Firepower Threat Defense (FTD) that allows the firewall to forward traffic at both layers 2 and 3 for the same subnet. In this mode, the firewall can act as a switch or a bridge to forward traffic at layer 2 and as a router to forward traffic at layer 3. This allows the firewall to maintain full control over the traffic, while still allowing it to forward traffic at both layers.
https://www.cisco.com/c/en/us/td/docs/security/firepower/ftd-config-guide/FTD-Config-Guide-v6/Integrated-Routing-and-Bridging.html


質問 # 119
展示を参照してください。

システム管理者は、ホストマシンからSCCMサーバーへの接続テストを実行しますが、サーバーからの応答はありません。pingパケットが宛先に到達し、ホストが応答を受信することを保証するアクションはどれですか?

  • A. ICMPトラフィックを許可するアクセス制御ポリシールールを作成します。
  • B. 検査後にICMPトラフィックを許可するようにカスタムSnort署名を構成します。
  • C. ICMP許可リストを作成し、ICMP宛先を追加して、暗黙の拒否リストから削除します。
  • D. ICMPトラフィックを許可するようにSnortルールを変更します。

正解:A


質問 # 120
エンジニアはネットワークに冗長性を組み込む必要があり、ファイアウォールの前にある冗長スイッチがダウンした場合でもトラフィックは継続的に流れる必要があります。このタスクを実行するには、何を構成する必要がありますか?

  • A. ファイアウォールダスターのインターフェイスモードに切り替わるvPC
  • B. ファイアウォールクラスターモードとスイッチの冗長インターフェース
  • C. ファイアウォールの非クラスターモードとスイッチの冗長インターフェース
  • D. ファイアウォールクラスター上のスパンEtherChannelへのスイッチ上のvPC

正解:D

解説:
Reference: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKSEC-2020.pdf


質問 # 121
クラスター化ユニット環境でサイト間VPNを設定することの欠点は何ですか?

  • A. すべてのクラスターユニットで同時にVPN接続を維持するには、スマートライセンスが必要です。
  • B. 新しいマスターユニットが選出されると、確立されたVPN接続のみが維持されます。
  • C. 新しいマスターユニットが選出された場合、VPN接続を再確立する必要があります。
  • D. VPN接続は、障害が発生したマスターユニットが回復した場合にのみ再確立できます。

正解:C


質問 # 122
CiscoUmbrellaをCiscoThreat Responseと統合している間、ネットワークセキュリティエンジニアは、ドメインのブロッキングをCisco ThreatResponseインターフェイスからCiscoUmbrellaに自動的にプッシュしたいと考えています。どのAPIがこの要件を満たしていますか?

  • A. 調査する
  • B. REST
  • C. 強制
  • D. レポート

正解:B


質問 # 123
2つのCiscoFTDデバイス間でハイアベイラビリティを実現するには、どの2つの条件を満たす必要がありますか。 (2つ選択してください。)

  • A. 同じNTP構成
  • B. 同じフラッシュメモリサイズ
  • C. 同数のインターフェース
  • D. 同じDHCP / PPoE構成
  • E. 同じホスト名

正解:A、C

解説:
https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html Conditions In order to create an HA between 2 FTD devices, these conditions must be met:
Same model
Same version (this applies to FXOS and to FTD - (major (first number), minor (second number), and maintenance (third number) must be equal)) Same number of interfaces Same type of interfaces Both devices as part of same group/domain in FMC Have identical Network Time Protocol (NTP) configuration Be fully deployed on the FMC without uncommitted changes Be in the same firewall mode: routed or transparent.
Note that this must be checked on both FTD devices and FMC GUI since there have been cases where the FTDs had the same mode, but FMC does not reflect this.
Does not have DHCP/Point-to-Point Protocol over Ethernet (PPPoE) configured in any of the interface Different hostname (Fully Qualified Domain Name (FQDN)) for both chassis. In order to check the chassis hostname navigate to FTD CLI and run this command


質問 # 124
管理対象デバイスをインラインで展開するための最小要件は何ですか?

  • A. インラインインターフェイス、MTU、モード
  • B. パッシブインターフェイス、MTU、モード
  • C. パッシブインターフェイス、セキュリティゾーン、MTU、モード
  • D. インラインインターフェイス、セキュリティゾーン、MTU、モード

正解:A

解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/ips_device_deployments_and_configuration.html


質問 # 125
デバイスの削除とCisco FMCへの再追加について正しいのは次のうちどれですか。 (2つ選択してください。)

  • A. 登録時にNATおよびVPNポリシーを再適用するオプションが利用できるので、ユーザーは登録の完了後にポリシーを再適用する必要はありません。
  • B. Cisco FMCにデバイスを再度追加する前に、デバイスにマネージャを追加する必要があります。
  • C. 登録時にNATおよびVPNポリシーを再適用するオプションは利用できないため、ユーザーは登録の完了後にポリシーを再適用する必要があります。
  • D. Cisco FMC Webインターフェイスは、アクセス制御ポリシーを再適用するようにユーザーに促します。
  • E. Cisco FMC Webインターフェイスでは、デバイスを削除して再度追加するオプションはありません。

正解:C、D

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Device_Management_Basics.html


質問 # 126
エンジニアが、Webサーバーに接続できないデバイスのトラブルシューティングを行っています。接続は、Cisco FTD内部インターフェイスから開始され、9443の非標準ポートを介して10.0.1.100に到達しようとしています。エンジニアが接続を試行しているホストは、IPアドレス10.20.10.20にあります。ネットワーク上のパケットに何が起こっているかを判断するために、エンジニアはFTDパケットキャプチャツールを使用することにしました。この問題のトラブルシューティングに必要な情報を収集するには、どのキャプチャ構成を使用する必要がありますか。
A)

B)

C)

D)

  • A. オプションD
  • B. オプションC
  • C. オプションB
  • D. オプションA

正解:C


質問 # 127
エンジニアがネットワークを保護するようにCiscoIPSを設定していて、ポリシーを展開する前にテストしたいと考えています。トラフィックフローを一定に保ちながら、各着信パケットのコピーを監視する必要があります。これらの要件を満たすには、どのIPSモードを実装する必要がありますか?

  • A. インラインタップ
  • B. 透明
  • C. ルーティング
  • D. パッシブ

正解:A


質問 # 128
レポートテンプレートを作成するとき、特定のサブネットのアクティビティのみを表示するように結果を制限するにはどうすればよいですか?

  • A. テーブルビューセクションをレポートに追加し、検索フィールドをCIDR形式のネットワークとして定義します。
  • B. Firepower Management Centerでカスタム検索を作成し、レポートの各セクションで選択します。
  • C. レポートの各セクションで、X軸としてIPアドレスを選択します。
  • D. レポートの詳細設定で入力パラメーターを追加し、タイプをネットワーク/ IPに設定します。

正解:D

解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Reports.html#87267


質問 # 129
インターフェイスにヒットするすべてのパケットをキャプチャするには、Cisco FTD CLIでどのコマンドを使用する必要がありますか?

  • A. WORDをキャプチャする
  • B. キャプチャトラフィック
  • C. キャプチャ
  • D. コアダンプパケットエンジンを有効にする

正解:B

解説:
Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html


質問 # 130
管理者は、ネットワークパフォーマンスを向上させるためにCisco FTDルールを最適化しており、特定のトラフィックタイプの検査をバイパスして、CiscoFTDの負荷を軽減したいと考えています。この目標を達成するには、どのポリシーを構成する必要がありますか?

  • A. アイデンティティ
  • B. URLフィルタリング
  • C. 侵入
  • D. プレフィルター

正解:D


質問 # 131
エンジニアは、Cisco FMC でリモート ストレージを設定する必要があります。構成のバックアップは、災害復旧のためにネットワーク上の安全な場所から入手できる必要があります。レポートは、監査人が Active Directory ログインでアクセスできる共有の場所にバックアップする必要があります。これらの目標を達成するために、エンジニアはどの戦略を使用する必要がありますか?

  • A. バックアップには SMB を使用し、レポートには NFS を使用します。
  • B. バックアップとレポートの両方に SMB を使用します。
  • C. バックアップとレポートの両方に NFS を使用します。
  • D. バックアップには SSH を使用し、レポートには NFS を使用します。

正解:B

解説:
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/system_configuration.html#ID-2241-00000551
"You cannot send backups to one remote system and reports to another, but you can choose to send either to a remote system and store the other on the Firepower Management Center."


質問 # 132
ネットワークエンジニアは、Cisco Security PacketAnalyzerと統合されたセカンダリCiscoFMCをセットアップします。セカンダリCiscoFMCがプライマリCiscoFMCと同期するとどうなりますか。

  • A. セカンダリCisco FMCは、同期後にCisco Security PacketAnalyzerと再統合する必要があります
  • B. プライマリとセカンダリのCiscoFMC間の同期が失敗します
  • C. セカンダリCisco FMC、Cisco Security PacketAnalyzerを統合するための既存の設定が上書きされます。
  • D. 既存の統合設定がプライマリCiscoFMCに複製されます

正解:C


質問 # 133
パケットキャプチャのトレースオプションを選択する利点は何ですか?

  • A. このオプションは、キャプチャされるパケットの数を制限します。
  • B. オプションは、パケットがドロップされたか成功したかを示します。
  • C. オプションは、宛先ホストが別のパスを介して応答するかどうかを示しました。
  • D. オプションは、各パケットの詳細をキャプチャします。

正解:A


質問 # 134
組織では、Cisco IPSがインラインモードで実行されており、トラフィックに悪意のあるアクティビティがないか検査しています。 Cisco IRSがトラフィックを受信したときに、トラフィックがドロップされない場合、トラフィックはどのようにして宛先に到達しますか。

  • A. 送信のためにCiscoASAインターフェイスにルーティングされます。
  • B. パケットが複製され、コピーが宛先に送信されます。
  • C. CiscoIPS外部インターフェイスから送信されます。
  • D. CiscoIPSインラインセットから再送信されます。

正解:A


質問 # 135
組織内のネットワークデバイスを管理および監視するためのネットワーク監視ツールを導入した後、Cisco FMCのMIBを手動でアップロードする必要があることに気付きました。どのフォルダにMIBファイルをアップロードしますか?

  • A. /sf/etc/DCEALERT.MIB
  • B. /etc/sf/DCMIB.ALERT
  • C. system/etc/DCEALERT.MIB
  • D. /etc/sf/DCEALERT.MIB

正解:D

解説:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa- firepower-module-user-guide-v541/Intrusion-External-Responses.pdf


質問 # 136
Cisco FMCで設定され、Cisco FTDに伝達されるOSPFルーティング機能はどれですか。 (2つ選択してください。)

  • A. OSPFパケットに対するMD5認証
  • B. OSPFパケットに対するSHA認証
  • C. 仮想リンク
  • D. IPv6機能を備えたOSPFv2
  • E. エリア境界ルータータイプ1 LSAフィルタリング

正解:A、C


質問 # 137
展示を参照してください。

また、エンジニアは攻撃リスクレポートを分析しており、ネットワーク上に新しいオペレーティングシステムのインスタンスが300を超えていることを発見しました。これらの新しいオペレーティングシステムを保護するためにFirepower構成はどのように更新されますか?

  • A. 管理者がCiscoFirepowerに修復推奨レポートを要求します
  • B. Cisco Firepowerは、ポリシーを更新するための推奨事項を提供します。
  • C. 管理者は手動でポリシーを更新します。
  • D. CiscoFirepowerはポリシーを自動的に更新します。

正解:B

解説:
Explanation
Ref:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Tailori


質問 # 138
エンジニアは、Cisco FTD デバイスの背後にあるエンドポイントとパブリック DNS サーバからの接続の問題を調査する必要があります。エンドポイントは名前解決クエリを実行できません。Snarl の判定を確認しながら、Cisco FTD 上で実際の DNS トラフィックをシミュレートすることで問題をトラブルシューティングするには、エンジニアはどのアクションを実行する必要がありますか?

  • A. Cisco FMC の Capture w/Trace ウィザードを使用します。
  • B. FTD CLI から system support firewall-engine-debug コマンドを実行します。
  • C. Cisco FMC でカスタム ワークフローを作成します。
  • D. FTD CLI から tcpdump を使用して Snort エンジン キャプチャを実行します。

正解:A

解説:
Explanation
The Capture w/Trace wizard in Cisco FMC allows you to capture packets on an FTD device and trace their path through the Snort engine. This can help you troubleshoot connectivity issues from an endpoint behind an FTD device and a public DNS server, as well as verify the Snort verdict for the DNS traffic. The Capture w/Trace wizard lets you specify the source and destination IP addresses, ports, and protocols for the packets you want to capture and trace, as well as the FTD device and interface where you want to perform the capture.
You can also apply filters to limit the capture size and duration. After you start the capture, you can ping the DNS server from the endpoint and then view the captured packets and their Snort verdicts in the FMC web interface2.
To use the Capture w/Trace wizard in Cisco FMC, you need to follow these steps2:
In the FMC web interface, navigate to Troubleshooting > Capture/Trace.
Click New Capture.
Choose an FTD device from the Device drop-down list.
Choose an interface from the Interface drop-down list.
Enter the source and destination IP addresses, ports, and protocols for the packets you want to capture and trace. For example, if you want to capture DNS queries from an endpoint with IP address 10.1.1.100 to a DNS server with IP address 8.8.8.8, you can enter these values:
Source IP: 10.1.1.100
Source Port: any
Destination IP: 8.8.8.8
Destination Port: 53
Protocol: UDP
Optionally, apply filters to limit the capture size and duration. For example, you can set the maximum number of packets to capture, the maximum capture file size, or the maximum capture time.
Click Start.
Ping the DNS server from the endpoint and wait for some packets to be captured.
Click Stop to stop the capture.
Click View Capture to see the captured packets and their Snort verdicts.
The other options are incorrect because:
Performing a Snort engine capture using tcpdump from the FTD CLI will not allow you to trace the path of the packets through the Snort engine or verify their Snort verdicts. Tcpdump is a command-line tool that can capture packets on an FTD device, but it does not provide any information about how Snort processes those packets or what actions Snort takes on them2.
Creating a Custom Workflow in Cisco FMC will not help you troubleshoot a connectivity issue from an endpoint behind an FTD device and a public DNS server. A Custom Workflow is a user-defined set of pages that display event data in different formats, such as tables, charts, maps, and so on. A Custom Workflow does not allow you to capture or trace packets on an FTD device3.
Running the system support firewall-engine-debug command from the FTD CLI will not allow you to simulate real DNS traffic on the FTD device or verify the Snort verdict for that traffic. The firewall-engine-debug command is a diagnostic tool that can generate synthetic packets and send them through the Snort engine on an FTD device. The synthetic packets are not real network traffic and do not affect any connections or policies on the FTD device4.


質問 # 139
非同期ルーティング構成を展開するときに、同じインラインインターフェイスセットに複数のインラインインターフェイスペアを追加する利点は何ですか?

  • A. インターフェースは自動ネゴシエーションを無効にし、インターフェース速度はハードコードされて1000Mbpsに設定されます。
  • B. Snortプロセスの再起動中に、トラフィック検査を中断することなく続行できます。
  • C. IPSがインバウンドトラフィックとアウトバウンドトラフィックを同じトラフィックフローの一部として識別できるようにします。
  • D. インターフェイスは、メディアに依存しないインターフェイスクロスオーバーとして自動的に構成されます。

正解:C


質問 # 140
......

最新の300-710日本語試験エンジンPDFで全部無料問題集保証:https://jp.fast2test.com/300-710J-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어