300-740 · Question #27
Refer to the exhibit. An engineer must block internal users from accessing Facebook and Facebook Apps. All other access must be allowed. The indicated policy was created in Cisco Secure Firewall…
The correct answer is D. Set Destination Zones to outside for rule 1. E. Set Source Zones to inside for rule 1. Options D and E are correct because Rule 1 is the block rule targeting Facebook/Facebook Apps, but without specifying Source Zone as inside (E) and Destination Zone as outside (D), the rule has no zone context and will never match the intended traffic - allowing it to fall…
Question
Refer to the exhibit. An engineer must block internal users from accessing Facebook and Facebook Apps. All other access must be allowed. The indicated policy was created in Cisco Secure Firewall Management Center and deployed to the internet edge firewall; however, users still can access Facebook. Which two actions must be taken to meet the requirement? (Choose two.)
Exhibit
Options
- ASet Destination Zones to outside for rule 2.
- BSet Source Zones to inside for rule 2.
- CSet Applications to Facebook and Facebook Apps for rule 2.
- DSet Destination Zones to outside for rule 1.
- ESet Source Zones to inside for rule 1.
How the community answered
(24 responses)- A8% (2)
- C13% (3)
- D79% (19)
Explanation
Options D and E are correct because Rule 1 is the block rule targeting Facebook/Facebook Apps, but without specifying Source Zone as inside (E) and Destination Zone as outside (D), the rule has no zone context and will never match the intended traffic - allowing it to fall through to the permit-all rule instead.
Why the distractors are wrong:
- A and B modify Rule 2 (the allow-all rule) - fixing zone settings on the wrong rule does nothing to block Facebook traffic.
- C would add Facebook/Facebook Apps to the allow rule (Rule 2), which is the opposite of the goal and would actively permit what you're trying to block.
Memory tip: In Cisco FMC, think of a rule as needing a complete "address" to work - Source Zone → Destination Zone → Application. A block rule with no zones is like a guard posted at no particular door; traffic walks right past it to the next rule. Always configure zones on deny rules first.
Topics
Community Discussion
No community discussion yet for this question.
