Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-710 Exam - Topic 11 Question 105 Discussion

A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomning networks. Which system settings must the administrator configure in Secure Firewall Management Center to meet the requirement?
B) Malware Policy. and C) Rules Intrusion Policy. Security Intelligence
A) Access Policy. Security Intelligence
D) Access Policy. Rules

Cisco 300-710 Exam - Topic 11 Question 105 Discussion

Actual exam question for Cisco's 300-710 exam
Question #: 105
Topic #: 11
[All 300-710 Questions]

A network administrator wants to configure a Cisco Secure Firewall Threat Defense instance managed by Cisco Secure Firewall Management Center to block traffic to known cryptomning networks. Which system settings must the administrator configure in Secure Firewall Management Center to meet the requirement?

Show Suggested Answer Hide Answer
Suggested Answer: B, C

To ensure high availability of internet access when deploying a pair of Cisco Secure Firewall Threat Defense (FTD) devices managed by Cisco Secure Firewall Management Center (FMC), the following features must be deployed:

Route Tracking: This feature monitors the reachability of a specified target (such as an external IP address) through the configured routes. If the route to the target is lost, the FTD can dynamically adjust the routing to use an alternate path, ensuring continuous internet access.

SLA Monitor: Service Level Agreement (SLA) monitoring works alongside route tracking to continuously verify the status and performance of the internet links. If the SLA for one of the ISP links fails (indicating the link is down or underperforming), the FTD can switch traffic to the secondary ISP link.

Steps to configure:

In FMC, navigate to Devices > Device Management.

Select the FTD device and configure route tracking to monitor the ISP links.

Configure SLA monitors to continuously check the health and performance of the internet circuits.

These configurations ensure that internet access remains available to users even if one of the ISPs goes down.


Contribute your Thoughts:

0/2000 characters
Teddy
9 months ago
Rules Intrusion Policy could also play a role, don’t overlook it!
upvoted 0 times
...
Brandon
9 months ago
I disagree, Malware Policy might be more effective here.
upvoted 0 times
...
Shawn
10 months ago
Wait, can you really block all cryptomining traffic? Sounds tricky.
upvoted 0 times
...
Berry
10 months ago
I think Access Policy is the way to go!
upvoted 0 times
...
Nidia
10 months ago
Definitely need to check the Security Intelligence settings.
upvoted 0 times
...
Xochitl
10 months ago
I’m leaning towards D, Access Policy. Rules, but I’m not confident. I need to double-check how rules are applied in this context.
upvoted 0 times
...
Shay
11 months ago
I practiced a similar question where we had to configure rules for blocking traffic. I feel like C, Rules Intrusion Policy. Security Intelligence could be relevant here too.
upvoted 0 times
...
Dorthy
11 months ago
I'm not entirely sure, but I remember something about Malware Policy being important for blocking specific types of traffic. Could it be B?
upvoted 0 times
...
Lanie
11 months ago
I think the answer might be A, Access Policy. Security Intelligence, because it seems like the right place to block known threats.
upvoted 0 times
...
Teddy
11 months ago
I think the key here is to focus on the specific requirement to block traffic to known cryptomining networks. That suggests we need to use the Security Intelligence feature, which allows you to block traffic to known malicious domains and IP addresses. So I'm going with A - Access Policy and Security Intelligence.
upvoted 0 times
...
Shayne
11 months ago
I'm a little confused by all the different policy options here. Is the Malware Policy also relevant, or is that just for malware detection? I want to make sure I fully understand the differences between all these policies before answering.
upvoted 0 times
...
Vernice
11 months ago
Okay, I've got this. The answer is A - Access Policy and Security Intelligence. The Security Intelligence feature allows you to block traffic to known malicious domains and IP addresses, which would include cryptomining networks. Easy peasy!
upvoted 0 times
...
Shaunna
11 months ago
Hmm, I'm a bit unsure about this one. I know we need to configure something in the Secure Firewall Management Center, but I'm not sure if it's the Access Policy, Malware Policy, or something else. I'll have to think this through carefully.
upvoted 0 times
...
Maira
11 months ago
This looks like a pretty straightforward question about configuring Cisco Secure Firewall Threat Defense. I think the key is to focus on the specific requirement to block traffic to known cryptomining networks.
upvoted 0 times
...
Aron
1 year ago
Security Intelligence? More like 'Security Cluelessness' if you ask me. That's so 2010.
upvoted 0 times
Amber
1 year ago
D: Access Policy. Rules
upvoted 0 times
...
Delmy
1 year ago
C: Rules Intrusion Policy. Security Intelligence
upvoted 0 times
...
Gracia
1 year ago
B: Malware Policy
upvoted 0 times
...
Iesha
1 year ago
A: Access Policy. Security Intelligence
upvoted 0 times
...
...
Georgiann
1 year ago
Ha! I bet the answer is 'All of the above.' Cisco loves to throw those kinds of trick questions at us.
upvoted 0 times
...
Sena
1 year ago
I think the administrator needs to configure both Access Policy and Security Intelligence. Gotta cover all the bases, you know?
upvoted 0 times
Cammy
1 year ago
D) Access Policy. Rules
upvoted 0 times
...
Marylyn
1 year ago
C) Rules Intrusion Policy. Security Intelligence
upvoted 0 times
...
Allene
1 year ago
B) Malware Policy.
upvoted 0 times
...
Thurman
1 year ago
A) Access Policy. Security Intelligence
upvoted 0 times
...
...
Krystina
1 year ago
Hmm, I'm not so sure. Wouldn't Malware Policy be the way to go? That seems more targeted for this kind of threat.
upvoted 0 times
...
Margurite
1 year ago
I'm not sure, but I think it could also be C) Rules Intrusion Policy. Security Intelligence. It's important to have the right rules in place to block specific types of traffic.
upvoted 0 times
...
Cheryl
1 year ago
I agree with Luther. Configuring Security Intelligence in Access Policy makes sense to block traffic to known cryptomining networks.
upvoted 0 times
...
Sheldon
1 year ago
Access Policy. Security Intelligence, of course! That's the obvious choice to block known cryptomining networks.
upvoted 0 times
...
Luther
1 year ago
I think the answer is A) Access Policy. Security Intelligence.
upvoted 0 times
...

Save Cancel