Share your SNCF Experience
September 29th, 2022
Go to comments
Please share with us your experience to prepare for the new SNCF 300-710 exam, your materials, the way you learned, your recommendations… But please DO NOT share any information about the detail of the exam or your personal information, your score, exam date and location, your email…
Your posts are warmly welcome! Hope you will find useful information here!



cftut when is the update going to happen?
Anyone passed recently? Which materials did you study?
Hi Cftut, when can we expect the update?
Hi, is it enough to pass?
looks like it was around end of January that people were still passing the exam easily and after started failing
@cftut please update the exam, my exam is in 10 days and only will purchase premium if I know it’s updated
LOOKAGAIN people is passing and they posted part of the questions here, the ones they saw. Sarch for the answers and you should be able to pass. The last one to pass was in March.
I will take the exam on thursday. Is anyone going this week? Can you share your experiance? thx
Hi guys,
How does one get access to the updated exam ?
Will I get that once I register as a premium? Please advise.
I’m going to take this examen in June, are the questions updated in premium?
just passed
About 10 new q and 5 very similar, but not 100% the same.
I think part 1-5 is not enough anymore. You need good understaning of the topics or big luck.
Can you identify the ones posted here: 10 to 15 new ones
1:
Check BGP route advertisment to upstream router cmd in FTD
Q2:
Secondary Static route cmd in FTD
Q3:
Span port configuration cmd on a switch (both source and destination ports were same in the choices and it was the only one which was making sense- because other options had wrong cmds
Q4:
new snipt – drag n drop – complete the pcap output result of a traceroute capture.
Q5:
wireshark output – client not being about to connect with a HTTP server – wiresharkout had tcp ACK output (with options like allow the FTD inside to allow ACk traffic or outside interface)
Q6:
suspicious website URL reputation setting in ACP URL filtering – suspicious / malware url reputation (options – questinable, untrusted etc)
Q7:
email report to mgmt about 24hr record of my configration changes on FTD – Cisco FMC FTD Configuration changes report —- answer Change Reconciliation.
Q8:
server is sending TCP rest to client over the internet – tell where to start the pcap on FTD to troubleshoot (server in DMZ interface, upstream router – outside interface,
ONE
A network administrator Sees ad attempt Attack from a specific IP address into cisco firepower manager Center Which Cisco Security tool Must Be Used directly from the Secure firewall Management Center web page to Find Out more information about the ip address
TWO
a security analyst is investigating a potential compromise in the network. the security analyst must produce a report for the suspicious activity from cisco secure firewall management center
THREE
what acts as the remediation module for rapid threat containment within cisco secure firewall management center
Thank you
anyone taking the exam?
please share the questions you come across in the exam and not in premium
@cftut please update the premium, more than 15 new questions in exam is very risky for us, one piece questions are helpful but not very clear
@CFTUT: Please please update the premium ASAP!
I did premium subscription and I failed – 50 % new questions
@CFTUT: on 27th-Dec-2025 you added 10 new questions and then on 17th-Feb-2026 3 questions
I have purchased the premium and been waiting for new questions to be added patiently, I need to take the exam in the next 12 days and if fail my exam status will expire.
Passed the exam 2 days ago. Got like 6 drag an drop. And like 10-20 new questions. It was hard, I barely pass it. Good luck to you guys.
@cftut kindly update the questions asap by next week. i must go for exam by late May to keep my certifications active. please do for all the people who had paid for the premium subscription.
Failed …15 new questions…Total was 61…
@cftut any plan on when the next update will be? Time to remove spam messages but don’t have to give assurance on the new questions?
any update on the new questions?
@CFTUT:
Hi Guys, this is not nice that even after being a premium members we are not getting the UPDATES ON THE QUESTIONS in time! PLEASE HURRY UP! as it seems like a bunch of us are going for exam pretty soon! Thanks
I will certainly do a charge back of the fee paid for premium if its not updated by the time I take the exam in few days.
anybody sat for the exam recently and passed with this dump, i’m planning to buy this premium voucher only if this is valid.
This dump only have few question that showed on the exam. Lots of new questions and drag and drop. Dont rely as much on this.
Recently passed the exam. All questions were from here ..Thanks TUT!!!!
These dumps are not enough… recently passed my exam but I had to cross check so many resources to make it and practiced some of the stuff for real. At least 10-15 new questions, so chance of mistakes! So definitely a refund!
just did the exam, I wouldn’t have sat the exam if I didn’t have too, there was around 25 or more new questions. this dump is invalid. also saw few questions that Kalger posted earlier in the exam
Check BGP route advertisment to upstream router cmd in FTD
Span port configuration cmd on a switch (both source and destination ports were same in the choices and it was the only one which was making sense- because other options had wrong cmds
wireshark output – client not being about to connect with a HTTP server – wiresharkout had tcp ACK output (with options like allow the FTD inside to allow ACk traffic or outside interface)
suspicious website URL reputation setting in ACP URL filtering – suspicious / malware url reputation (options – questinable, untrusted etc)
email report to mgmt about 24hr record of my configration changes on FTD – Cisco FMC FTD Configuration changes report —- answer Change Reconciliation.
server is sending TCP rest to client over the internet – tell where to start the pcap on FTD to troubleshoot (server in DMZ interface, upstream router – outside interface,
A network administrator Sees ad attempt Attack from a specific IP address into cisco firepower manager Center Which Cisco Security tool Must Be Used directly from the Secure firewall Management Center web page to Find Out more information about the ip address
ISE, secure endpoint, …
a security analyst is investigating a potential compromise in the network. the security analyst must produce a report for the suspicious activity from cisco secure firewall management center
what acts as the remediation module for rapid threat containment within cisco secure firewall management center
ACP question, answer is 1- to allow the host 2-block the whole subnet
how to configure ACP that only triggers during a specific timeline
what firewall mode to configure that sends traffic to internet but does not impact the flow of traffic
to create a widget on fmc dashboard to show the interface
it was very stressful as every other question or 2-3 questions back to back where new and I only remember fragments, not enough to help you, sorry, the point is there were too many new questions and having paid for premium we should get regular updates, it is now end of May and cftut only added 3 new questions back in feb, not good at all
Anyone tried ExamTopics
Is this thread dead? Any point in waiting
hi guys! anyone recently took the exam? whats your experience?
Took it a couple of weeks back. Lots of new questions. This list is incomplete.
@PolarBear Thx for the info..are the questions here enough to pass the exam? Thx
Not enough, I have failed the exam.
I took the exam 2 days ago and passed. About 85% of the questions were still from the premium materials, while the rest were new. I suggest reviewing as well the new questions posted by “invalid,” as I encountered them during the exam.
How does Akat secure an 85% premium, especially since most previous clients/takers claim the opposite is true?
I’m confused about what to believe. Many people said they failed due to a lot of new questions, so how is the latest comment claiming there’s a high percentage of exam questions in the dumps?
How many questions are in premium version?
pay and you will know
@Scavenger “Pay and you will know” isn’t really an answer. I’m asking for information from users who already have access.
1. How do you check BGP route advertisements toward an upstream router on Cisco FTD?
show bgp ipv4 unicast neighbors advertised-routes
show ip bgp neighbors advertised-routes
2. What is the correct cisco switch command structure to configure a local SPAN session?
monitor session 1 source interface GigabitEthernet1/0/1
monitor session 1 destination interface GigabitEthernet1/0/24
3. If a packet capture shows TCP ACKs but the client cannot establish a proper HTTP connection, what should be checked first on the firewall?
whether the 3-way handshake completed
whether the ACP / prefilter / NAT is allowing the session
whether return traffic is permitted
whether the packet capture point is correct (inside vs outside vs DMZ)
4. Which URL reputation category is typically used to block clearly risky or malicious destinations in URL filtering?
Reputation Threat Level Description
Trusted Displaying behavior that indicates exceptional safety
Favorable Displaying behavior that indicates a level of safety
Neutral Displaying neither positive or negative behavior. However, has been evaluated.
Questionable Displaying behavior that may indicate risk, or could be undesirable
Untrusted Displaying behavior that is exceptionally bad, malicious, or undesirable
Unknown Not previously evaluated, or lacking features to assert a threat level verdict
5. Management report showing configuration changes for the last 24 hours
Change Reconciliation Report
6. If a DMZ server is sending TCP RSTs to an Internet client, where is the best place to begin packet capture on the FTD?
Capture at DMZ interface → did server send RST?
Capture at outside interface → did FTD forward it outward?
If necessary, compare directions to see if firewall policy/NAT is altering behavior
If the question asks where to start, choose the interface nearest the device believed to originate the RST.
7. Which Cisco security integration/tool can be launched from FMC to get more intelligence about a suspicious IP address?
Cisco SecureX / SecureX Threat Response (depending on exam/version wording)
FMC integrates with Cisco security ecosystem tools for threat intelligence and investigation workflows.
8. What should be used in FMC to generate a report on suspicious activity detected in the network?
Use FMC reporting based on relevant event data, such as:
Intrusion events
Connection events
Malware events
Security intelligence events
Correlation events
A custom report or relevant built-in report using the appropriate event type is typically the right approach.
9. Which component provides remediation capability for Rapid Threat Containment in a Cisco Secure Firewall environment?
This usually ties into integrations such as Cisco ISE for adaptive network enforcement / quarantine actions.
Threat detection may come from one platform, but remediation/enforcement is commonly driven through ecosystem integration.
10. How should ACP rules be ordered if one specific host in a subnet must be allowed, but the rest of the subnet must be blocked?
Place the allow rule for the specific host first
Place the block rule for the larger subnet after it
ACP rules are evaluated top-down, first match.
11. How do you make an ACP rule active only during a specific time period?
Use a Time Range / Time-based rule condition associated with the access control rule.
12. Which firewall mode allows traffic visibility to the Internet without impacting traffic flow?
Tap Mode
13. What type of widget/customization is used on the FMC dashboard to display interface-related information?
Use a dashboard widget / custom dashboard widget that pulls the relevant interface metric or health data.
oh, that’s an answer. it’s just not the one you want.
nicely done redman
Just cleared my exam. Whoever says this dump is not enough to clear the exam is not going to clear any exam. This dump is still valid. Yes, the 80% questions came from this dump and you can refer to kagel and my previous comment for new question. Hurry up Cisco will update this question starting Aug 2026. My next task is to write juniper.
Just passed the exam.
Cftut Still relevant but there were new questions.
Passed yesterday.
The questions were very valid to me with a couple caveats:
*15 or so new questions but they are in the comments except 2/3
*the most I’ve seen Cisco play with the words to introduce confusion
*memorizing a dump isn’t enough. U will have to understand the concepts/platforms/basic route
Below- Questions/Concepts/Answers from the chat that helped me…
300-710
Newest Questions from Social Media chats…
1. How do you check BGP route advertisements toward an upstream router on Cisco FTD?
show bgp ipv4 unicast neighbors advertised-routes
show ip bgp neighbors advertised-routes
2. What is the correct cisco switch command structure to configure a local SPAN session?
monitor session 1 source interface GigabitEthernet1/0/1
monitor session 1 destination interface GigabitEthernet1/0/24
3. If a packet capture shows TCP ACKs but the client cannot establish a proper HTTP connection, what should be checked first on the firewall?
whether the 3-way handshake completed
whether the ACP / prefilter / NAT is allowing the session
-whether return traffic is permitted
whether the packet capture point is correct (inside vs outside vs DMZ)
4. Which URL reputation category is typically used to block clearly risky or malicious destinations in URL filtering?
-Reputation Threat Level Description
Trusted Displaying behavior that indicates exceptional safety
Favorable Displaying behavior that indicates a level of safety
Neutral Displaying neither positive or negative behavior. However, has been evaluated.
Questionable Displaying behavior that may indicate risk, or could be undesirable
-Untrusted Displaying behavior that is exceptionally bad, malicious, or undesirable
Unknown Not previously evaluated, or lacking features to assert a threat level verdict
5. Management report showing configuration changes for the last 24 hours
Change Reconciliation Report
6. If a DMZ server is sending TCP RSTs to an Internet client, where is the best place to begin packet capture on the FTD?
Capture at DMZ interface → did server send RST?
Capture at outside interface → did FTD forward it outward?
If necessary, compare directions to see if firewall policy/NAT is altering behavior
If the question asks where to start, choose the interface nearest the device believed to originate the RST.
19. Server is sending TCP rest to client over the internet – tell where to start the pcap on FTD to troubleshoot
-upstream router – outside interface
7. Which Cisco security integration/tool can be launched from FMC to get more intelligence about a suspicious IP address?
Cisco SecureX / SecureX Threat Response (depending on exam/version wording)
FMC integrates with Cisco security ecosystem tools for threat intelligence and investigation workflows.
8. What should be used in FMC to generate a report on suspicious activity detected in the network?
Use FMC reporting based on relevant event data, such as:
Intrusion events
Connection events
Malware events
Security intelligence events
Correlation events
A custom report or relevant built-in report using the appropriate event type is typically the right approach.
9. Which component provides remediation capability for Rapid Threat Containment in a Cisco Secure Firewall environment?
This usually ties into integrations such as Cisco ISE for adaptive network enforcement / quarantine actions.
Threat detection may come from one platform, but remediation/enforcement is commonly driven through ecosystem integration
17. What acts as the remediation module for rapid threat containment within cisco secure firewall management center
-ISE
10. How should ACP rules be ordered if one specific host in a subnet must be allowed, but the rest of the subnet must be blocked?
Place the allow rule for the specific host first
Place the block rule for the larger subnet after it
ACP rules are evaluated top-down, first match.
11. How do you make an ACP rule active only during a specific time period?
Use a Time Range / Time-based rule condition associated with the access control rule.
12. Which firewall mode allows traffic visibility to the Internet without impacting traffic flow?
Tap Mode
13. What type of widget/customization is used on the FMC dashboard to display interface-related information?
custom dashboard widget that pulls the relevant interface metric or health data.
14. Secondary Static route cmd in FTD
-Primary Route
#route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
-Secondary (Backup) Route
#route outside 0.0.0.0 0.0.0.0 10.0.0.1 254
15. A network administrator Sees ad attempt Attack from a specific IP address into cisco firepower manager Center Which Cisco Security tool Must Be Used directly from the Secure firewall Management Center web page to Find Out more information about the ip address
-Whois Lookup and Geolocation Lookup tools. ISE, secure endpoint, …
16. A security analyst is investigating a potential compromise in the network. the security analyst must produce a report for the suspicious activity from cisco secure firewall management center
-Analysis > Intrusions > Events dashboard. Filter your data for the specific time frame or threat, and use the built-in Report Designer or Reporting icon to export the targeted malicious events.
18. Wireshark output – client not connecting with a HTTP server – wireshark output had tcp ACK output (with options like allow the FTD inside to allow ACk traffic or outside interface)
– TCP Handshake failures, Access Control List (ACL) drops, or MTU
20. how to configure an ACP that only triggers during a specific time
-FTD Policies > Access Control > edit your ACP > Select the rule > Edit > Time Range tab > Add to create a new Time Range
-ISE Policies > Policy Elements > Conditions > Time and Date > Add
Go to Policy > Authorization > Authorization Policy rule > Under the Conditions column, add the newly created Time and Date condition to the rule > Save the policy
21. How to create a widget on fmc dashboard to show the interface
– FMC Dashboard > Add Widget menu > Custom Widget
Passed today. New questions mostly came out for me except for number 14. Good Luck to everyone.
1. How do you check BGP route advertisements toward an upstream router on Cisco FTD?
show bgp ipv4 unicast neighbors advertised-routes
show ip bgp neighbors advertised-routes
2. What is the correct cisco switch command structure to configure a local SPAN session?
monitor session 1 source interface GigabitEthernet1/0/1
monitor session 1 destination interface GigabitEthernet1/0/3
3. If a packet capture shows TCP ACKs but the client cannot establish a proper HTTP connection, what should be checked first on the firewall?
whether the 3-way handshake completed
whether the ACP / prefilter / NAT is allowing the session
-whether return traffic is permitted
whether the packet capture point is correct (inside vs outside vs DMZ)
4. Which URL reputation category is typically used to block clearly risky or malicious destinations in URL filtering?
-Reputation Threat Level Description
Trusted Displaying behavior that indicates exceptional safety
Favorable Displaying behavior that indicates a level of safety
Neutral Displaying neither positive or negative behavior. However, has been evaluated.
Questionable Displaying behavior that may indicate risk, or could be undesirable
-Untrusted Displaying behavior that is exceptionally bad, malicious, or undesirable
Unknown Not previously evaluated, or lacking features to assert a threat level verdict
5. Management report showing configuration changes for the last 24 hours
Change Reconciliation Report
6. If a DMZ server is sending TCP RSTs to an Internet client, where is the best place to begin packet capture on the FTD?
Capture at DMZ interface → did server send RST?
Capture at outside interface → did FTD forward it outward?
If necessary, compare directions to see if firewall policy/NAT is altering behavior
If the question asks where to start, choose the interface nearest the device believed to originate the RST.
19. Server is sending TCP rest to client over the internet – tell where to start the pcap on FTD to troubleshoot
-upstream router – outside interface
7. Which Cisco security integration/tool can be launched from FMC to get more intelligence about a suspicious IP address?
Cisco SecureX / SecureX Threat Response (depending on exam/version wording)
FMC integrates with Cisco security ecosystem tools for threat intelligence and investigation workflows.
8. What should be used in FMC to generate a report on suspicious activity detected in the network?
Use FMC reporting based on relevant event data, such as:
Intrusion events
Connection events
Malware events
Security intelligence events
Correlation events
A custom report or relevant built-in report using the appropriate event type is typically the right approach.
9. Which component provides remediation capability for Rapid Threat Containment in a Cisco Secure Firewall environment?
This usually ties into integrations such as Cisco ISE for adaptive network enforcement / quarantine actions.
Threat detection may come from one platform, but remediation/enforcement is commonly driven through ecosystem integration
17. What acts as the remediation module for rapid threat containment within cisco secure firewall management center
-ISE
10. How should ACP rules be ordered if one specific host in a subnet must be allowed, but the rest of the subnet must be blocked?
Place the allow rule for the specific host first
Place the block rule for the larger subnet after it
ACP rules are evaluated top-down, first match.
11. How do you make an ACP rule active only during a specific time period?
Use a Time Range / Time-based rule condition associated with the access control rule.
12. Which firewall mode allows traffic visibility to the Internet without impacting traffic flow?
Tap Mode
13. What type of widget/customization is used on the FMC dashboard to display interface-related information?
custom dashboard widget that pulls the relevant interface metric or health data.
14. Secondary Static route cmd in FTD
-Primary Route
#route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
-Secondary (Backup) Route
#route outside 0.0.0.0 0.0.0.0 10.0.0.1 254
15. A network administrator Sees ad attempt Attack from a specific IP address into cisco firepower manager Center Which Cisco Security tool Must Be Used directly from the Secure firewall Management Center web page to Find Out more information about the ip address
-Whois Lookup and Geolocation Lookup tools. ISE, secure endpoint, …
16. A security analyst is investigating a potential compromise in the network. the security analyst must produce a report for the suspicious activity from cisco secure firewall management center
-Analysis > Intrusions > Events dashboard. Filter your data for the specific time frame or threat, and use the built-in Report Designer or Reporting icon to export the targeted malicious events.
18. Wireshark output – client not connecting with a HTTP server – wireshark output had tcp ACK output (with options like allow the FTD inside to allow ACk traffic or outside interface)
– TCP Handshake failures, Access Control List (ACL) drops, or MTU
20. how to configure an ACP that only triggers during a specific time
-FTD Policies > Access Control > edit your ACP > Select the rule > Edit > Time Range tab > Add to create a new Time Range
-ISE Policies > Policy Elements > Conditions > Time and Date > Add
Go to Policy > Authorization > Authorization Policy rule > Under the Conditions column, add the newly created Time and Date condition to the rule > Save the policy
21. How to create a widget on fmc dashboard to show the interface
– FMC Dashboard > Add Widget menu > Custom Widget
Passed last week, got all the new questions mentioned above, so make sure you understand them.
And practice all the questions in Parts 1-5. And do the Composite Tests.
Good luck.