nerdexam
Cisco

300-710 · Question #78

A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the loc

The correct answer is D. creating an ACP with an INSIDE_NET network object and object overrides. To maintain policy consistency across multiple branch locations while accommodating local network variations, use object overrides for a shared network object within a common Access Control Policy.

Configuration

Question

A security engineer is configuring an Access Control Policy for multiple branch locations. These locations share a common rule set and utilize a network object called INSIDE_NET which contains the locally significant internal network subnets at each location. What technique will retain the policy consistency at each location but allow only the locally significant network subnet within the applicable rules?

Options

  • Autilizing policy inheritance
  • Butilizing a dynamic ACP that updates from Cisco Talos
  • Ccreating a unique ACP per device
  • Dcreating an ACP with an INSIDE_NET network object and object overrides

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    10% (3)
  • D
    79% (23)

Why each option

To maintain policy consistency across multiple branch locations while accommodating local network variations, use object overrides for a shared network object within a common Access Control Policy.

Autilizing policy inheritance

While policy inheritance exists in some systems, object overrides are the specific mechanism for customizing shared objects within a consistent policy in Cisco Firepower Management Center (FMC).

Butilizing a dynamic ACP that updates from Cisco Talos

A dynamic ACP updating from Cisco Talos is related to threat intelligence feeds, not to customizing local network objects for different branches.

Ccreating a unique ACP per device

Creating a unique ACP per device would lead to policy inconsistencies and negate the goal of a common rule set.

Dcreating an ACP with an INSIDE_NET network object and object overridesCorrect

Object overrides allow a single Access Control Policy (ACP) to be deployed across multiple devices or domains, where a specific object (like INSIDE_NET) can have different values (e.g., different local subnets) on each device. This maintains a consistent policy structure while providing the necessary local customization.

Concept tested: Cisco FMC object overrides

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/policies-and-rules.html

Topics

#Access Control Policy#Network Objects#Object Overrides#Cisco Firepower

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice