exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 115 discussion

Actual exam question from Cisco's 300-710
Question #: 115
Topic #: 1
[All 300-710 Questions]

An engineer is investigating connectivity problems on Cisco Firepower that is using service group tags. Specific devices are not being tagged correctly, which is preventing clients from using the proper policies when going through the firewall. How is this issue resolved?

  • A. Use traceroute with advanced options
  • B. Use Wireshark with an IP subnet filter
  • C. Use a packet capture with match criteria
  • D. Use a packet sniffer with correct filtering
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d0980cc
2 weeks, 6 days ago
Selected Answer: C
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos231/web-guide/b_GUI_FXOS_ConfigGuide_231/troubleshooting.html#:~:text=34525%2C%20ARP%20%3D%202054%2C-,and%20SGT%20%3D%2035081),-.
upvoted 1 times
...
houhou12322
7 months, 3 weeks ago
I think it has something to do with AMP for endpoint and cisco secure client because in the question they say "preventing clients from using the proper policies"
upvoted 1 times
...
THEODORABLE
1 year, 11 months ago
My choice is C, this is a Cisco Exam, why would we choose WireShark instead of a native Cisco process on a cisco device for the same purpose? Plus with Wireshark you would need to span a port for data flow.
upvoted 3 times
...
Joe_Blue
2 years, 1 month ago
Selected Answer: C
Yes, using a packet capture with match criteria would be a good way to troubleshoot this issue. The packet capture can be set up to capture traffic only from the specific devices that are not being tagged correctly. The match criteria can be set to filter for traffic that is associated with the service group in question, allowing the engineer to see if the traffic is being tagged correctly or not. Based on the results of the packet capture, the engineer can then take appropriate actions to resolve the issue.
upvoted 2 times
...
Baumb
2 years, 3 months ago
Im voting for C, because a packet capture on the FW always makes more sense than doing something on the client
upvoted 3 times
...
dique
2 years, 8 months ago
Selected Answer: C
Correct answer is: C
upvoted 2 times
...
xziomal9
2 years, 9 months ago
Selected Answer: C
Correct answer is: C
upvoted 2 times
...
aadach
3 years, 1 month ago
Answer C
upvoted 2 times
...
trickbot
3 years, 2 months ago
C, Using the built in Packet Capture feature is the best answer. B is NOT the best answer because: This is not a test on Wireshark You wouldnt necessarily use a subnet filter If B were right, than D would be even more right. We can do packet captures right in FMC, including filtering for specific SGTs.
upvoted 2 times
...
netwguy
3 years, 8 months ago
C also makes sense. Capture could just be exported and imported in wireshark. Also, you would be able to use match argument to specify devices instead of subnet, and also SGTs if you want to. I will go for C if this comes up during test.
upvoted 3 times
...
cryptofetti
3 years, 8 months ago
B, Wireshark makes the most sense
upvoted 1 times
...
kakakayayaya
3 years, 11 months ago
Why don't we use packet capture? Arguable answer...
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago