Free 350-701 Exam Braindumps (page: 14)

Page 14 of 153

Which CLI command is used to register a Cisco FirePower sensor to Firepower Management Center?

  1. configure system add <host><key>
  2. configure manager <key> add host
  3. configure manager delete
  4. configure manager add <host><key

Answer(s): D



Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention
System?

  1. Correlation
  2. Intrusion
  3. Access Control
  4. Network Discovery

Answer(s): D

Explanation:

The Firepower System uses network discovery and identity policies to collect host, application, and user data for traffic on your network. You can use certain types of discovery and identity data to build a comprehensive map of your network assets, perform forensic analysis, behavioral profiling, access control, and mitigate and respond to the vulnerabilities and exploits to which your organization is susceptible. You can configure your network discovery policy to perform host and application detection.


Reference:

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc- configguide-v64/introduction_to_network_discovery_and_identity.html



Which ASA deployment mode can provide separation of management on a shared appliance?

  1. DMZ multiple zone mode
  2. transparent firewall mode
  3. multiple context mode
  4. routed mode

Answer(s): C



Refer to the exhibit.



What is a result of the configuration?

  1. Traffic from the DMZ network is redirected
  2. Traffic from the inside network is redirected
  3. All TCP traffic is redirected
  4. Traffic from the inside and DMZ networks is redirected

Answer(s): D

Explanation:

The purpose of above commands is to redirect traffic that matches the ACL "redirect-acl" to the Cisco FirePOWER (SFR) module in the inline (normal) mode. In this mode, after the undesired traffic is dropped and any other actions that are applied by policy are performed, the traffic is returned to the ASA for further processing and ultimate transmission.

The command "service-policy global_policy global" applies the policy to all of the interfaces.


Reference:

https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644- configurefirepower-00.html



Page 14 of 153



Post your Comments and Discuss Cisco® 350-701 exam with other Community members:

David A commented on January 16, 2024
Good Colombia
Anonymous
upvote

Kim commented on May 25, 2023
I just purchased and downloaded my files. Everything looks good so far.
UNITED STATES
upvote