nerdexam
Cisco

300-710 · Question #182

Refer to the exhibit. An engineer is modifying an access control policy to add a rule to inspect all DNS traffic that passes through the firewall. After making the change and deploying the policy…

The correct answer is D. The action of the rule is set to trust instead of allow. If DNS traffic is not being inspected by the Snort engine after an access control policy deployment in Cisco FTD/FMC, the problem is likely that the action of the rule configured for DNS traffic is set to 'Trust' instead of 'Allow'.

Configuration

Question

Refer to the exhibit. An engineer is modifying an access control policy to add a rule to inspect all DNS traffic that passes through the firewall. After making the change and deploying the policy, they see that DNS traffic is not being inspected by the Snort engine. What is the problem?

Exhibit

300-710 question #182 exhibit

Options

  • AThe rule must specify the security zone that originates the traffic.
  • BThe rule is configured with the wrong setting for the source port.
  • CThe rule must define the source network for inspection as well as the port.
  • DThe action of the rule is set to trust instead of allow.

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    11% (3)
  • D
    78% (21)

Why each option

If DNS traffic is not being inspected by the Snort engine after an access control policy deployment in Cisco FTD/FMC, the problem is likely that the action of the rule configured for DNS traffic is set to 'Trust' instead of 'Allow'.

AThe rule must specify the security zone that originates the traffic.

While specifying security zones is good practice, it would not inherently prevent Snort inspection if the traffic matches the rule otherwise and the action is 'Allow'.

BThe rule is configured with the wrong setting for the source port.

The question implies the rule is for 'DNS traffic', meaning the port (53) is correctly identified; if the port were wrong, traffic would not match the rule at all, not just fail inspection.

CThe rule must define the source network for inspection as well as the port.

Defining the source network is part of traffic identification for a rule, but not directly responsible for enabling Snort inspection once traffic matches a rule, as the action dictates inspection.

DThe action of the rule is set to trust instead of allow.Correct

In Cisco FTD/FMC, an access control rule with the action 'Trust' bypasses all deeper inspection by the Snort engine, including intrusion policies, file policies, and malware inspection. For Snort inspection to occur, the rule's action must be 'Allow' (or 'Block' if inspection is followed by a block).

Concept tested: Cisco FTD/FMC Access Control Policy rule actions and Snort inspection

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/access_control_rules.html

Topics

#Access Control Policy#Threat Inspection#Cisco FTD#Snort Engine

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice