300-610 · Question #202
Refer to the exhibit. The security team created a new security policy that requires certain types of traffic to be subject to deep packet inspection. The traffic types are: - internet traffic to appli
The correct answer is A. one-armed insertion from the core switch cluster. The security team requires deep packet inspection for specific traffic types (internet to servers/users, partner to servers/users) and needs to determine the optimal firewall insertion point.
Question
Refer to the exhibit. The security team created a new security policy that requires certain types of traffic to be subject to deep packet inspection. The traffic types are:
- internet traffic to application servers
- internet traffic to corporate users
- partner network traffic to application servers
- partner network traffic to corporate users
Where must the next-generation firewalls be inserted to implement the new policy?
Exhibit
Options
- Aone-armed insertion from the core switch cluster
- Binline insertion between the edge router duster and the core switch duster
- Cone-armed insertion from the ACl border leaf duster
- Dinline insertion between the user network switch cluster and the core cluster
How the community answered
(47 responses)- A72% (34)
- B15% (7)
- C9% (4)
- D4% (2)
Why each option
The security team requires deep packet inspection for specific traffic types (internet to servers/users, partner to servers/users) and needs to determine the optimal firewall insertion point.
Inline insertion between the edge router cluster and the core switch cluster would primarily inspect North-South traffic between the internet and the internal network, but might not efficiently capture or redirect partner network traffic or specific internal server-to-user traffic for deep inspection.
One-armed insertion from the ACI border leaf cluster would be specific to an ACI environment and might not be the most appropriate or generic placement for inspecting all specified traffic types without knowing the full ACI design and traffic flow patterns.
Inline insertion between the user network switch cluster and the core cluster primarily inspects user-to-core traffic, potentially missing internet-to-server or partner-to-server traffic flows that do not traverse this specific segment.
Concept tested: Next-Generation Firewall deployment models for inspection
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/fpmc-config-guide-70_chapter_0110.html
Topics
Community Discussion
No community discussion yet for this question.
