exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 299 discussion

Actual exam question from Cisco's 300-710
Question #: 299
Topic #: 1
[All 300-710 Questions]

When packet capture is used on a Cisco Secure Firewall Threat Defense device and the packet flow is waiting on the malware query, which Snort verdict appears?

  • A. block
  • B. retry
  • C. replace
  • D. blockflow
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MooseMullay
Highly Voted 6 months, 1 week ago
Selected Answer: B
Looks like retry based on the following link: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/troubleshooting_the_system.html
upvoted 7 times
...
Nian
Most Recent 1 week, 1 day ago
Selected Answer: B
Retry is correct. BlockFlow: Snort has determined that the entire flow or session should be blocked. https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/troubleshooting_the_system.html#:~:text=on%20passive%20interfaces.-,Retry,-Flow%20is%20stalled
upvoted 1 times
...
gwb
7 months, 2 weeks ago
D. BlockFlow Verdict: The BlockFlow verdict is specific to Snort. When a packet receives the BlockFlow verdict, it is dropped immediately, and subsequent packets in the same session are also dropped before reaching Snort. Essentially, it prevents any further processing of that flow. Use Cases: Malware Detection: For example, if Snort identifies a packet as malicious (e.g., malware), it may assign the BlockFlow verdict to prevent any additional communication from that source.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago