CCNP Security 300-710 SNCF Practice Test 12

CCNP Security 300-710 SNCF Practice Test 12 (Hard) - DNS Policy and Identity Policy Configuration

CISCO CCNP Security Exam Logo

1 / 10

Which FMC policy type allows administrators to block DNS resolution for known-malicious or categorized domains as part of the traffic inspection pipeline?

2 / 10

Which DNS policy rule condition would allow an administrator to block resolution of domains associated with a specific threat intelligence category, such as known command-and-control domains?

3 / 10

Which FMC policy type allows administrators to associate network traffic with specific user identities, enabling identity-aware access control and reporting?

4 / 10

Which identity policy configuration element defines the connection to a directory service, such as Active Directory, including the server address and directory search base used to resolve user and group information?

5 / 10

Which identity policy authentication method allows users to be identified transparently based on data collected from sources such as Active Directory logs, without prompting the user for credentials directly at the firewall?

6 / 10

Which identity policy authentication method requires the user to explicitly provide credentials through a browser-based prompt before being granted network access?

7 / 10

Which access control policy capability becomes possible once an identity policy has successfully associated traffic with a specific user or user group?

8 / 10

Which combination of DNS policy and identity policy capabilities would help an organization enforce different DNS filtering rules for known malicious domains while also reporting on which specific user generated a blocked DNS request?

9 / 10

Which practical benefit does identity-aware access control provide over relying solely on IP address-based rules in an environment with DHCP-assigned addresses and frequently roaming laptops?

10 / 10

Which combination of identity policy design choices would provide the most seamless user experience while still ensuring accurate identity mapping for an organization using Active Directory, with minimal explicit login prompts?

Your score is

The average score is 0%

0%