300-710 · Question #78
A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the loc
The correct answer is D. creating an ACP with an INSIDE_NET network object and object overrides. To maintain policy consistency across multiple branch locations while accommodating local network variations, use object overrides for a shared network object within a common Access Control Policy.
Question
A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location. What technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?
Options
- Autilizing policy inheritance
- Butilizing a dynamic ACP that updates from Cisco Talos
- Ccreating a unique ACP per device
- Dcreating an ACP with an INSIDE_NET network object and object overrides
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C10% (3)
- D79% (23)
Why each option
To maintain policy consistency across multiple branch locations while accommodating local network variations, use object overrides for a shared network object within a common Access Control Policy.
While policy inheritance exists in some systems, object overrides are the specific mechanism for customizing shared objects within a consistent policy in Cisco Firepower Management Center (FMC).
A dynamic ACP updating from Cisco Talos is related to threat intelligence feeds, not to customizing local network objects for different branches.
Creating a unique ACP per device would lead to policy inconsistencies and negate the goal of a common rule set.
Object overrides allow a single Access Control Policy (ACP) to be deployed across multiple devices or domains, where a specific object (like INSIDE_NET) can have different values (e.g., different local subnets) on each device. This maintains a consistent policy structure while providing the necessary local customization.
Concept tested: Cisco FMC object overrides
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/policies-and-rules.html
Topics
Community Discussion
No community discussion yet for this question.