nerdexam
Cisco

300-740 · Question #6

Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping…

The correct answer is D. Move rule 4 Access Controlled Groups to the top. Option D is correct because Cisco Secure Firewall Management Center evaluates access control rules top-down, applying the first matching rule and ignoring the rest. If a broader "allow" rule appears above rule 4, it matches restricted users' traffic first and permits it before…

Network and Cloud Security

Question

Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping websites. The indicated policy was applied; however, the restricted users still can browse on the mobile phone shopping websites during business hours. What should be done to meet the requirement?

Exhibit

300-740 question #6 exhibit

Options

  • ASet Dest Zones to Business Mobile Phones Shopping.
  • BSet Dest Networks to Business Mobile Phones Shopping.
  • CSet Time Range for rule 4 of Access Controlled Groups to All.
  • DMove rule 4 Access Controlled Groups to the top.

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    5% (1)
  • C
    5% (1)
  • D
    79% (15)

Explanation

Option D is correct because Cisco Secure Firewall Management Center evaluates access control rules top-down, applying the first matching rule and ignoring the rest. If a broader "allow" rule appears above rule 4, it matches restricted users' traffic first and permits it before rule 4 ever gets evaluated - moving rule 4 to the top ensures the block fires first.

Why the distractors fail:

  • A is wrong because "Business Mobile Phones Shopping" is a URL category, not a destination zone - destination zones refer to network interface segments (inside, outside, DMZ), not web content types.
  • B is wrong for the same reason - destination networks are IP address ranges, not URL or application categories.
  • C is wrong because changing the time range to "All" broadens when the rule applies but does nothing to fix the rule ordering problem; the rule still gets skipped if a higher rule already matches.

Memory tip: Think of FMC rules like a bouncer checklist - the first rule that matches "wins" and the rest are ignored. Whenever a block rule isn't working, ask "is something above it letting traffic through first?" - the fix is almost always order, not configuration of the rule itself.

Topics

#firewall rule precedence#access control policies#rule ordering#policy enforcement

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice