Skip to content

300-210 Practice Questions

Prepare for 300-210 with more than an answer.

230 questions in the full set17 sample questionsUpdated Jan 30, 2026

Unlock the full exam and previous versions

  • v1Standard 238 questions Locked
  • 300-210Legacy Security Implementing Cisco Threat Control Solutions (SITCS) 230 questions Current
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 5
  1. Content Security27%
  2. Network Threat Defense22%
  3. Cisco FirePOWER Next-Generation IPS (NGIPS)20%
  4. Troubleshooting, Monitoring, and Reporting Tools14%
  5. Cisco Security Manager and Other Tools17%
  1. 1

    Which TWO Cisco ESA features are specifically designed to protect against 'Zero-Day' email threats that have not yet been identified by traditional signature-based antivirus engines? (Select TWO)

    Show answer details

    Correct answer: C, D

    Outbreak Filters use global traffic patterns to identify suspicious anomalies before signatures are available, quarantining messages temporarily.

    AMP uses file reputation and sandboxing (Threat Grid) to analyze unknown files behaviorally, effectively catching zero-day malware that passes signature checks.

  2. 2

    When configuring a Cisco WSA Decryption Policy, which setting allows the appliance to inspect HTTPS traffic without generating certificate warnings for end-users visiting banking websites?

    Show answer details

    Correct answer: B

    The 'Pass Through' action allows the encrypted traffic to flow without being decrypted by the WSA. This preserves the original server certificate, preventing browser warnings for sites (like banking) where the organization cannot or should not act as a Man-in-the-Middle.

  3. 3

    True or False: In a Cisco Firepower deployment, the 'Security Intelligence' pre-filter policy is processed AFTER the Access Control Policy rules are evaluated.

    Show answer details

    Correct answer: B

    False. Security Intelligence is processed very early in the packet processing flow, BEFORE the Access Control Policy rules. This allows the system to drop traffic from known bad IPs/URLs immediately, saving resources by not subjecting that traffic to deep packet inspection rules.

  4. 4

    An administrator observes that the Cisco Firepower Management Center (FMC) dashboard is showing a 'High Impact' alert for an intrusion event. What specific configuration in the Firepower system determines this 'Impact' rating?

    Show answer details

    Correct answer: A

    The Impact Flag (Vulnerable, Potentially Vulnerable, etc.) is determined by correlating the attack signature with the target host's profile (OS, services, patches) discovered by Firepower. A 'High Impact' means the target is known to be vulnerable to that specific exploit.

  5. 5

    A network security engineer is configuring the Cisco AMP for Endpoints connector. They need to ensure that the connector does not interfere with the performance of a proprietary database application that writes heavily to a specific directory. Which configuration element should be modified?

    Show answer details

    Correct answer: B

    Exclusion Sets allow administrators to define paths, file extensions, or processes that the AMP connector should ignore. This is best practice for high-IO applications like databases to prevent performance degradation.

  6. 6

    Which three operating systems are supported with Cisco AMP for Endpoints? (Choose three.) A.WindowsB.AWSC.AndroidD.Cisco IOSE.OS XF.ChromeOS

    Show answer details

    Correct answer: A, C, E

  7. 7

    Which Cisco Web Security Appliance feature enables the appliance to block suspicious traffic on all of its ports and IP addresses? A.explicit forward modeB.Layer 4 Traffic MonitorC.transparent modeD.Secure Web Proxy

    Show answer details

    Correct answer: B

  8. 8

    Which feature requires the network discovery policy for it to work on the Cisco Next Generation Intrusion Prevention System? A.impact flagsB.URL filteringC.security intelligenceD.health monitoring

    Show answer details

    Correct answer: C

Create an account to continue.