nerdexam
Cisco

300-740 · Question #31

Refer to the exhibit. An engineer is analyzing a Cisco Secure Firewall Management Center report. Which activity does the output verify?

The correct answer is D. A DNS response from IP address 10.1.108.100 was blocked. Option D is correct because the exhibit's FMC report shows a blocked event on port 53 (DNS) with traffic originating from IP 10.1.108.100, which indicates a DNS response - DNS servers send responses back to clients, so the source IP identifies the server that replied. Why the…

Visibility and Assurance

Question

Refer to the exhibit. An engineer is analyzing a Cisco Secure Firewall Management Center report. Which activity does the output verify?

Exhibit

300-740 question #31 exhibit

Options

  • AAn HTTP response from IP address 10.1.104.101 was blocked.
  • BAn HTTP request to IP address 10.1.113.7 was blocked.
  • CA DNS request to IP address 172.17.1.2 was blocked.
  • DA DNS response from IP address 10.1.108.100 was blocked.

How the community answered

(36 responses)
  • A
    11% (4)
  • B
    3% (1)
  • C
    8% (3)
  • D
    78% (28)

Explanation

Option D is correct because the exhibit's FMC report shows a blocked event on port 53 (DNS) with traffic originating from IP 10.1.108.100, which indicates a DNS response - DNS servers send responses back to clients, so the source IP identifies the server that replied.

Why the distractors are wrong:

  • A is incorrect because the blocked traffic is DNS (port 53), not HTTP (port 80/443), and the IP 10.1.104.101 doesn't match the source shown.
  • B is incorrect for the same protocol mismatch (HTTP vs. DNS), and a request would show the DNS server as the destination, not the source.
  • C is incorrect because the direction is wrong - a DNS request originates from a client heading to a server (172.17.1.2 would be the destination), whereas the exhibit shows the blocked traffic coming from an IP, indicating a response.

Memory tip: Think of DNS traffic like a conversation - a request goes to the server, a response comes from the server. In FMC logs, the source IP tells you who sent the packet, so a source IP on port 53 = the server responding, not the client requesting.

Topics

#DNS response blocking#Firewall reporting#Log analysis#Traffic verification

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice