nerdexam
Cisco

300-710 · Question #425

Refer to the exhibit. A Cisco Secure Firewall Management Center, 7.0 device fails to receive intelligence feed updates. The Cisco Secure Firewall Management Center is configured to use a proxy…

The correct answer is D. Bypass the proxy server for intelligence.sourcefire.com. When a proxy server performs SSL inspection (man-in-the-middle decryption), it intercepts HTTPS connections and re-signs them with the proxy's own certificate. Cisco FMC validates the certificate chain when downloading intelligence feeds from intelligence.sourcefire.com; if the…

Management and Troubleshooting

Question

Refer to the exhibit. A Cisco Secure Firewall Management Center, 7.0 device fails to receive intelligence feed updates. The Cisco Secure Firewall Management Center is configured to use a proxy server that performs SSL inspection. Which action allows the Cisco Secure Firewall Management Center device to download the intelligence feed updates?

Exhibit

300-710 question #425 exhibit

Options

  • AInstall a self-signed certificate on the proxy server for intelligence.sourcefire.com.
  • BVerify that the proxy server can use HTTPS to communicate to the internet.
  • CEnsure that proxy authentication is disabled for the Cisco Secure Firewall Management
  • DBypass the proxy server for intelligence.sourcefire.com.

How the community answered

(17 responses)
  • A
    18% (3)
  • B
    6% (1)
  • C
    6% (1)
  • D
    71% (12)

Explanation

When a proxy server performs SSL inspection (man-in-the-middle decryption), it intercepts HTTPS connections and re-signs them with the proxy's own certificate. Cisco FMC validates the certificate chain when downloading intelligence feeds from intelligence.sourcefire.com; if the proxy substitutes its own certificate, the certificate validation fails and the download is blocked. The cleanest solution is to configure the proxy to bypass SSL inspection for intelligence.sourcefire.com, allowing FMC to receive the authentic certificate from Sourcefire's servers and complete the TLS handshake successfully. Installing a self-signed cert on the proxy (Option A) does not resolve the trust issue unless that cert is also trusted by FMC.

Topics

#Intelligence feeds#Proxy server#SSL inspection#Update management

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice