nerdexam
Cisco

300-740 · Question #29

Refer to the exhibit. An engineer must create a firewall policy to allow web server communication only. The indicated firewall policy was applied; however, a recent audit requires that all firewall…

The correct answer is A. Rules 3 and 4. Rules 3 and 4 are the correct rules to delete because they are redundant - they duplicate the functionality already covered by earlier rules (typically rules 1 and 2 that permit HTTP and HTTPS traffic), meaning any traffic matching Rules 3 and 4 would have already been handled…

Network and Cloud Security

Question

Refer to the exhibit. An engineer must create a firewall policy to allow web server communication only. The indicated firewall policy was applied; however, a recent audit requires that all firewall policies be optimized. Which set of rules must be deleted?

Exhibits

300-740 question #29 exhibit 1
300-740 question #29 exhibit 2

Options

  • ARules 3 and 4
  • BRules 2 to 4
  • CRules 2 to 5
  • DRules 1 and 5

How the community answered

(54 responses)
  • A
    59% (32)
  • B
    6% (3)
  • C
    11% (6)
  • D
    24% (13)

Explanation

Rules 3 and 4 are the correct rules to delete because they are redundant - they duplicate the functionality already covered by earlier rules (typically rules 1 and 2 that permit HTTP and HTTPS traffic), meaning any traffic matching Rules 3 and 4 would have already been handled before reaching them. Deleting them reduces policy bloat without changing traffic behavior, which is exactly what firewall optimization targets. Option B (Rules 2–4) is wrong because Rule 2 is a necessary permit rule for web traffic and removing it would break communication. Option C (Rules 2–5) is wrong for the same reason, plus Rule 5 is typically the deny-all catch-all rule that must be retained to block non-web traffic. Option D (Rules 1 and 5) is wrong because Rule 1 is the first essential web-traffic permit, and Rule 5 (deny-all) is a security baseline that should never be removed.

Memory tip: Think "shadow and shadow." A rule is deletable when it is shadowed - a preceding rule already matches the same traffic, so the shadowed rule is never reached. If you can remove a rule and traffic flow is identical, it's a candidate for deletion.

Topics

#firewall policy optimization#access control rules#policy analysis#rule redundancy

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice