Exam 300-710 All QuestionsBrowse all questions from this exam
Question 212

An engineer must investigate a connectivity issue from an endpoint behind a Cisco FTD device and a public DNS server. The endpoint cannot perform name resolution queries. Which action must the engineer perform to troubleshoot the issue by simulating real DNS traffic on the Cisco FTD while verifying the Snort verdict?

    Correct Answer: A

    To troubleshoot a connectivity issue related to DNS traffic and verify the Snort verdict, the engineer should use the Capture w/Trace wizard in Cisco FMC. This tool allows simulating real DNS traffic and tracing packet flow through the Firepower Threat Defense (FTD) device, providing detailed insights into the traffic path and Snort engine processing.

Discussion
JoninjimboOption: A

I would also say A. The requirements are "troubleshoot the issue by simulating real DNS traffic" .. this would indicate using optiong A which includes a Trace to simulate the traffic flow.

aaInman

A - is 100% correct.

eafea4fOption: A

TCPdump doesn't simulate packets.

c946f3eOption: A

A: See reference https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html

c946f3eOption: A

A To trace a real packet is very useful to troubleshoot connectivity issues. It allows you to see all the internal checks that a packet goes through. Add the trace detail keywords and specify the number of packets that you want to be traced. By default, the FTD traces the first 50 ingress packets. In this case, enable capture with trace detail for the first 100 packets that FTD receives on the INSIDE interface: > capture CAPI2 interface INSIDE trace detail trace-count 100 match icmp host 192.168.103.1 host 192.168.101.1