Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cisco CCNP Security 300-740 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 300-740 Premium Access

View all detail and faqs for the 300-740 exam


702 Students Passed

92% Average Score

94% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Question # 11

Refer to the exhibit. An engineer must configure Cisco ASA so that the Secure Client deployment is removed when the user laptop disconnects from the VPN. The indicated configuration was applied to the Cisco ASA firewall. Which command must be run to meet the requirement?

Options:

A.

client-bypass-protocol enable

B.

anyconnect keep-installer none

C.

anyconnect firewall-rule client-interface

D.

D. client-bypass-protocol disable

Questions # 12:

An organization is distributed across several sites. Each site is connected to the main HQ using site-to-site VPNs implemented using Secure Firewall Threat Defense. Which functionality must be implemented if the security manager wants to send SaaS traffic directly to the internet?

Options:

A.

Multi-instances

B.

IPsec tunnels

C.

Policy-based routing

D.

ECMP routing

Questions # 13:

Question # 13

Refer to the exhibit. A security engineer deployed Cisco Secure XDR, and during testing, the log entry shows a security incident. Which action must the engineer take first?

Options:

A.

Uninstall the malware.

B.

Block IP address 10.77.17.45.

C.

Isolate the endpoint.

D.

Rebuild the endpoint.

Questions # 14:

In the zero-trust network access model, which criteria is used for continuous verification to modify trust levels?

Options:

A.

System patching status

B.

Detected threat levels

C.

User and device behavior

D.

Network traffic patterns

Questions # 15:

Which SAFE component logically arranges the security capabilities into blueprints?

Options:

A.

Reference Architectures

B.

Cisco Validated Designs

C.

Places in the Network

D.

Secure Domains

Questions # 16:

An administrator must deploy an endpoint posture policy for all users. The organization wants to have all endpoints checked against antimalware definitions and operating system updates and ensure that the correct Secure Client modules are installed properly. How must the administrator meet the requirements?

Options:

A.

Configure the WLC to provide local posture services, and configure Cisco ISE to receive the compliance verification from the WLC to be used in an authorization policy.

B.

Create an ASA Firewall posture policy, upload the Secure Client images to the NAD, and create a local client provisioning portal.

C.

Create the required posture policy within Cisco ISE, configure redirection on the NAD, and ensure that the client provisioning policy is correct.

D.

Identify the antimalware being used, create an endpoint script to ensure that it is updated, and send the update log to Cisco ISE for processing.

Questions # 17:

Question # 17

Refer to the exhibit. An engineer must create a segmentation policy in Cisco Secure Workload to block HTTP traffic. The indicated configuration was applied; however, HTTP traffic is still allowed. What should be done to meet the requirement?

Options:

A.

Change consumer_filter_ref to HTTP Consumer.

B.

Add HTTP to 14_params.

C.

Decrease the priority of the template to 50.

D.

Increase the priority of the template to 200.

Questions # 18:

Question # 18

Question # 18

Refer to the exhibit. An engineer is investigating an unauthorized connection issue using Cisco Secure Cloud Analytics. Which two actions must be taken? (Choose two.)

Options:

A.

Reinstall the host from a recent backup.

B.

Inform the incident management team.

C.

Validate the IDS logs

D.

Block the unwanted IP addresses on the firewall

E.

Reinstall the host from scratch.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.