2026年最新ののCisco 300-740リアル試験問題集PDF
300-740試験問題集、300-740練習テスト問題
質問 # 114
What is the primary purpose of implementing identity certificates for user and device authentication?
- A. To monitor user activity
- B. To increase network speed
- C. To track device locations
- D. To ensure secure access to resources
正解:D
質問 # 115
When determining security policies for application enforcement, which of the following is a key consideration?
- A. The popularity of the application among users
- B. The color scheme of the application interface
- C. The sensitivity of the data being accessed or stored by the application
- D. The programming language used to develop the application
正解:C
質問 # 116
OIDC (OpenID Connect) is primarily utilized for:
- A. Disconnecting user sessions
- B. Monitoring user activities
- C. Increasing network latency
- D. Authenticating users via an identity provider
正解:D
質問 # 117
Based on telemetry reports, actions might include adjusting _________ to better protect against identified threats.
- A. office layouts
- B. security policies
- C. hiring practices
- D. marketing strategies
正解:B
質問 # 118 
Refer to the exhibit. An engineer must configure Duo SSO for Cisco Webex and add the Webex application to the Duo Access Gateway. Which two actions must be taken in Duo? (Choose two.)
- A. Configure the Applications settings for Cisco Webex.
- B. Upload the SAML application JSON file.
- C. Add a new application to the Duo platform.
- D. Import the Identity Provider metadata.
- E. Upload the application XML metadata file.
正解:C、D
解説:
To integrate Cisco Webex with Duo SSO using the Duo Access Gateway, the engineer must:
E: Add Cisco Webex as a new SAML application to Duo.
C: Configure the Webex application settings, including Entity ID, Assertion Consumer Service URL, and signing requirements.
Uploading XML metadata (Option A) is typically used when importing IdP settings, not for Duo application configuration. JSON (Option B) is not used in SAML-based Duo app configurations.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 2:
User and Device Security, Pages 42-45
質問 # 119
Direct-internet-access for trusted business applications is beneficial for:
- A. Reducing latency and improving access to cloud resources
- B. Increasing security risks by exposing applications to the internet
- C. Enhancing the user experience by providing quicker access
- D. Simplifying the network architecture
正解:A、C、D
質問 # 120 

Refer to the exhibit. An engineer must configure VPN load balancing across two Cisco ASA. The indicated configuration was applied to each firewall; however, the load-balancing encryption scheme fails to work.
Which two commands must be run on each firewall to meet the requirements? (Choose two.)
- A. encryption aes 256
- B. hash sha-256
- C. crypto ikev1 policy 1
- D. cluster encryption
- E. cluster port 9024
正解:A、D
解説:
To enable VPN load balancing with secure encryption between Cisco ASA firewalls, two additional commands are required:
encryption aes 256: Defines the encryption scheme used in the load balancing cluster. Without specifying encryption, secure key exchanges between devices will not occur properly.
cluster encryption: Enables encrypted communication between the clustered ASA devices. Without this command, cluster member synchronization is not securely established.
The commands shown in the exhibit correctly configure the cluster key and virtual IP but lack the necessary encryption parameters. According to Cisco's VPN load balancing implementation guides and reinforced in the SCAZT documentation, these two settings are required to secure the VPN session load distribution.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 3:
Network and Cloud Security, Pages 72-75; Cisco ASA VPN Load Balancing Configuration Guide
質問 # 121
The main goal of implementing secure domains within the SAFE framework is to:
- A. Enhance the flexibility of network configurations
- B. Increase operational efficiency
- C. Improve security by creating defined areas of trust
- D. Simplify the user authentication process
正解:C
質問 # 122
Response automation in cybersecurity is primarily used for:
- A. Decreasing the speed of response to security incidents
- B. Reducing the accuracy of threat detection
- C. Automating the process of detecting and responding to threats
- D. Increasing the workload of cybersecurity teams
正解:C
質問 # 123
Which method is used by a Cisco XDR solution to prioritize actions?
- A. Updating antivirus signatures
- B. Leveraging AI and machine learning
- C. Monitoring endpoint activity
- D. Analyzing network traffic patterns
正解:B
解説:
Cisco XDR (Extended Detection and Response) leverages artificial intelligence (AI) and machine learning (ML) to prioritize actions based on the severity, context, and impact of detected threats. According to the Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT) documentation, Cisco XDR consolidates telemetry from endpoints, networks, cloud, email, and identity sources and applies AI/ML models to reduce alert fatigue, correlate signals, and surface only the highest-risk threats for response.
This intelligent correlation and prioritization mechanism enables security analysts to focus on critical incidents first, dramatically reducing mean time to detect (MTTD) and mean time to respond (MTTR). Unlike static mechanisms such as antivirus updates or passive traffic inspection, AI-driven analytics enable Cisco XDR to make data-informed decisions across the entire attack surface.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 6:
Threat Response, Pages 113-117
質問 # 124
Multifactor authentication enhances security by requiring:
- A. A single security question
- B. A username only for identification
- C. Only a simple password
- D. Multiple verification methods before granting access
正解:D
質問 # 125 

Refer to the exhibit. An engineer must connect an on-premises network to the public cloud using Cisco Umbrella as a Cloud Access Security Broker. The indicated configuration was applied to router R1; however, connectivity to Umbrella fails with this error: %OPENDNS-3-DNS_RES_FAILURE. Which action must be taken on R1 to enable the connection?
- A. Add the opendns out command to the interface configuration.
- B. Configure a DHCP scope using the ip dhcp pool command.
- C. Add the opendns in command to the interface configuration.
- D. Configure the Open DNS servers with the ip name-server command.
正解:D
解説:
The error %OPENDNS-3-DNS_RES_FAILURE indicates a failure to resolve DNS queries via Cisco Umbrella. The most common cause of this error is the router lacking DNS resolution capability. To resolve this, the router must be explicitly configured to use Cisco Umbrella's OpenDNS servers by adding the following to global configuration:
According to the SCAZT guide (Section 1: Cloud Security Architecture, Pages 17-19), Umbrella enforces cloud-based DNS-layer protection, and upstream devices must be properly configured with working DNS name servers to perform redirection and inspection.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 1, Pages 17-19
質問 # 126
The final step in handling a security incident, after containment and remediation, is to _________ the affected systems or applications to their normal state.
- A. abandon
- B. dismantle
- C. quarantine
- D. reinstantiate
正解:D
質問 # 127 
Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping websites. The indicated policy was applied; however, the restricted users still can browse on the mobile phone shopping websites during business hours. What should be done to meet the requirement?
- A. Set Time Range for rule 4 of Access Controlled Groups to All.
- B. Set Dest Zones to Business Mobile Phones Shopping.
- C. Move rule 4 Access Controlled Groups to the top.
- D. Set Dest Networks to Business Mobile Phones Shopping.
正解:C
解説:
In Cisco Secure Firewall Management Center (FMC), access control policies are processed top-down- meaning the first matching rule is applied, and the remaining are ignored. Based on the exhibit, Rule 4 (Access Controlled Groups) is likely being shadowed by a broader rule above it that permits web traffic. To ensure restricted users are denied access to mobile phone shopping categories, Rule 4 must be moved to the top of the rule hierarchy.
Cisco SCAZT (Section 5: Visibility and Assurance, Pages 94-97) describes best practices for rule ordering and inspection logic. Moving the specific block rule (Rule 4) higher ensures it's enforced before general allow rules are evaluated.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 5, Pages 94-97
質問 # 128
What helps prevent drive-by compromise?
- A. Browsing known websites
- B. Ad blockers
- C. Incognito browsing
- D. VPN
正解:B
解説:
A drive-by compromise occurs when malicious code is automatically downloaded and executed simply by visiting a compromised website-often through malicious advertising scripts (malvertising). According to SCAZT Section 4: Application and Data Security (Pages 85-87), ad blockers help prevent drive-by downloads by blocking these third-party ad scripts and redirections, which are commonly used in such attacks.
VPNs and private browsing modes (e.g., Incognito) do not provide protection against malicious content hosted on web pages.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 4, Pages 85-87
=========
質問 # 129
An organization is distributed across several sites. Each site is connected to the main HQ using site-to-site VPNs implemented using Secure Firewall Threat Defense. Which functionality must be implemented if the security manager wants to send SaaS traffic directly to the internet?
- A. Multi-instances
- B. ECMP routing
- C. Policy-based routing
- D. IPsec tunnels
正解:C
解説:
Policy-Based Routing (PBR) enables routing decisions based on criteria such as source IP, destination IP, or application. To send SaaS traffic (e.g., Office 365, Salesforce) directly to the internet rather than over a site-to- site VPN, PBR must be configured at each site firewall. According to SCAZT Section 1 (Cloud Security Architecture, Pages 18-20), this approach enables secure local internet breakout-commonly used in direct internet access (DIA) architectures.
Reference: Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT), Section 1, Pages 18-20
質問 # 130
Secure Domains in the SAFE framework are used to:
- A. Specify security policies for cloud providers
- B. Categorize types of security threats
- C. Define different administrative roles
- D. Segregate network areas based on security requirements
正解:D
質問 # 131
......
Cisco 300-740 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
PDF問題(2026年最新)実際のCisco 300-740試験問題:https://www.jpntest.com/shiken/300-740-mondaishu
問題集返金保証付きの300-740問題集には90%オフ:https://drive.google.com/open?id=1AkK7iu2YCtOzXf5iPJon1aiTz0DIEQHo