nerdexam
Cisco

300-610 · Question #202

Refer to the exhibit. The security team created a new security policy that requires certain types of traffic to be subject to deep packet inspection. The traffic types are: - internet traffic to appli

The correct answer is A. one-armed insertion from the core switch cluster. The security team requires deep packet inspection for specific traffic types (internet to servers/users, partner to servers/users) and needs to determine the optimal firewall insertion point.

Security

Question

Refer to the exhibit. The security team created a new security policy that requires certain types of traffic to be subject to deep packet inspection. The traffic types are:

  • internet traffic to application servers
  • internet traffic to corporate users
  • partner network traffic to application servers
  • partner network traffic to corporate users

Where must the next-generation firewalls be inserted to implement the new policy?

Exhibit

300-610 question #202 exhibit

Options

  • Aone-armed insertion from the core switch cluster
  • Binline insertion between the edge router duster and the core switch duster
  • Cone-armed insertion from the ACl border leaf duster
  • Dinline insertion between the user network switch cluster and the core cluster

How the community answered

(47 responses)
  • A
    72% (34)
  • B
    15% (7)
  • C
    9% (4)
  • D
    4% (2)

Why each option

The security team requires deep packet inspection for specific traffic types (internet to servers/users, partner to servers/users) and needs to determine the optimal firewall insertion point.

Aone-armed insertion from the core switch clusterCorrect
Binline insertion between the edge router duster and the core switch duster

Inline insertion between the edge router cluster and the core switch cluster would primarily inspect North-South traffic between the internet and the internal network, but might not efficiently capture or redirect partner network traffic or specific internal server-to-user traffic for deep inspection.

Cone-armed insertion from the ACl border leaf duster

One-armed insertion from the ACI border leaf cluster would be specific to an ACI environment and might not be the most appropriate or generic placement for inspecting all specified traffic types without knowing the full ACI design and traffic flow patterns.

Dinline insertion between the user network switch cluster and the core cluster

Inline insertion between the user network switch cluster and the core cluster primarily inspects user-to-core traffic, potentially missing internet-to-server or partner-to-server traffic flows that do not traverse this specific segment.

Concept tested: Next-Generation Firewall deployment models for inspection

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/fpmc-config-guide-70_chapter_0110.html

Topics

#Network Security#Firewall deployment#Deep Packet Inspection#Traffic Steering

Community Discussion

No community discussion yet for this question.

Full 300-610 Practice