300-710 · Question #287
Which default action setting in a Cisco FTD Access Control Policy allows all traffic from an undefined application to pass without Snort inspection?
The correct answer is D. Trust All Traffic. In a Cisco FTD Access Control Policy, the "Trust All Traffic" default action allows all traffic, including that from undefined applications, to pass without Snort inspection.
Question
Which default action setting in a Cisco FTD Access Control Policy allows all traffic from an undefined application to pass without Snort inspection?
Options
- ANetwork Discovery Only
- BInherit from Base Policy
- CIntrusion Prevention
- DTrust All Traffic
How the community answered
(25 responses)- A4% (1)
- B8% (2)
- D88% (22)
Why each option
In a Cisco FTD Access Control Policy, the "Trust All Traffic" default action allows all traffic, including that from undefined applications, to pass without Snort inspection.
Network Discovery Only would allow traffic to pass but would still perform network discovery, not necessarily bypassing all Snort inspection, and it's not a common default action for simply allowing traffic without inspection.
Inherit from Base Policy implies the action is determined by a parent policy, which doesn't directly define the behavior for "undefined application" traffic.
Intrusion Prevention explicitly enables Snort inspection, which is the opposite of the requirement to pass traffic without Snort inspection.
The "Trust All Traffic" action in an FTD Access Control Policy is designed to permit traffic without any Snort-based intrusion inspection, file policy inspection, or malware inspection. This effectively bypasses deeper security analysis for trusted or undefined applications, allowing them to pass through.
Concept tested: FTD Access Control Policy default actions and Snort inspection
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/fpmc-access-policies.html#concept_63795C62070D48119098EF0C04F09B17
Topics
Community Discussion
No community discussion yet for this question.