Test #2 Flashcards
(193 cards)
Which command must be run to generate troubleshooting files on an FTD?
a. system support view-files
b. sudo sf_troubleshoot.pl
c. system generate-troubleshoot all
C
Which two packet captures does the FTD LINA engine support? (Choose Two)
A. Layer 7 Network ID
B. Source IP
C. Application IP
D. Dynamic Firewall Importing
E. Protocol
Source
Protocol
Which two features of AMP for Endpoints allow for an uploaded file to be blocked? (Choose Two)
A. application blocking
B. Simple Custom detection
C. File repository
D. exclusions
E. application whitelisting
Application Blocking
Simple Custom Detection
On the Advanced tab under inline set properties, which allows interfaces to emulate a passive interface?
A. transparent inline mode
B. TAP mode
C. strict TCP enforcement
D. propagate link state
Tap mode
With Cisco Threat Defense software, which interface mode must be configured to passively receive traffic that passes through the appliance?
A. inline set
B. passive
C. routed
D. inline tap
Inline Tap
What are 2 types or forms of suppression on a Firepower Policy?
A. Source
B. port
C. rule
D. protocol
E. Application
Source
Rule
Which Cisco Firepower Threat Defense, which two interface settings are required when configuring a routed interface? (Choose Two)
Speed
Duplex
What are two application layer preprocessors?
IMAP
SSL
Which two OSPF routing features are configured in the Cisco FMC and propagted to the FTD?
Virtual Links
MD5
With Cisco FTD software, which interface mode do you configure for an IPS deployment, where traffic passes through the appliance but does not require VLAN rewriting?
Routed
Which two fields can be used to create a new email alert within the Cisco FMC under Policies -> Actions -> Alerts Tab?
From
Relay Host
What is the disadvantage of setting up site-to-site VPN in a clustered-units enviroment?
VPN connections must be reestablished when a new master unit is elected.
What are two statement about Bridge-group interfaces in FTD are true?
BGs are supported in Routed and Transparent
Each directly connectd network must be on the same subnet
Which two routing protocols options are valid with Cisco FTD?
BGPv6
ECMP with a single interface
Which two TCP ports can allow the CIsco FMC to communicate with FireAMP cloud for File dispostion information?
443
32137
Which FP feature allows users to configure bridges in routed mode and enables devices to perform Layer 2 switching between interfaces?
IRB
Which two places can thresholding settings be configured?
On each IPS rule
Globally, per intrusion policy
In which two ways do access control policies operate on a Cisco Firepower system?
Traffic inspection can be interrupted temporarily when configuration changes are deployed
They can block traffic based on Security Intelligence Data
Which two types of objects re reusable and supported by FMC?
Reputation based objects that represent security intelligence
Network based objects that represent IP addresses
What are two characteristics represented a Cisco device operating in TAP mode?
It analyzes copies of packets from the packet flow
The packet flow traverses the device
When using AMP for network, which feature copies a file to the Cisco AMP Cloud for analysis?
Dynamic
WHich command line mode is supported from the Cisco Firepower Management Center CLI?
Configuration
What command is entered in the Cisco FMC CLI to generate a troubleshooting file?
sudo sf_troubleshoot.pl
While configuring FTD, a network engineer wants to ensure that traffic passing through the appliance does not require routing or VLAN rewriting.
Which interface mode should the engineer implement to accomplish this task?
Inline SET