300-710 · Question #387
A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal users from downloading…
The correct answer is D. access policy rule that allows users to reach the internet and assigns a file policy that blocks. To prevent internal users from downloading executable files from the internet, the administrator needs to configure an access control policy rule that: 1. Allows users to access the internet. 2. Applies a file policy to the rule that blocks executable file downloads. In Cisco…
Question
A network administrator is configuring an instance of Cisco Secure Firewall Threat Defense, which is registered to Cisco Secure Firewall Management Center, to prevent internal users from downloading executable files from the internet. What must be created and configured by the administrator to meet the requirement?
Options
- Afile policy that blocks downloads of all executable files and applies the file policy to the default
- Baccess policy rule that allows users to reach the internet with a second rule that blocks application
- Cfile policy rule that allows users to reach the internet with a second rule applied that blocks
- Daccess policy rule that allows users to reach the internet and assigns a file policy that blocks
How the community answered
(29 responses)- A10% (3)
- B14% (4)
- C3% (1)
- D72% (21)
Explanation
To prevent internal users from downloading executable files from the internet, the administrator needs to configure an access control policy rule that: 1. Allows users to access the internet. 2. Applies a file policy to the rule that blocks executable file downloads. In Cisco Secure Firewall Threat Defense, file policies are used to inspect file types being transmitted and take appropriate actions, such as blocking or allowing files based on their type. The file policy must be assigned to an access policy rule to enforce it for specific traffic.
Topics
Community Discussion
No community discussion yet for this question.