300-740 · Question #6
Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping…
The correct answer is D. Move rule 4 Access Controlled Groups to the top. Option D is correct because Cisco Secure Firewall Management Center evaluates access control rules top-down, applying the first matching rule and ignoring the rest. If a broader "allow" rule appears above rule 4, it matches restricted users' traffic first and permits it before…
Question
Refer to the exhibit. An engineer must create a policy in Cisco Secure Firewall Management Center to prevent restricted users from being able to browse any business or mobile phone shopping websites. The indicated policy was applied; however, the restricted users still can browse on the mobile phone shopping websites during business hours. What should be done to meet the requirement?
Exhibit
Options
- ASet Dest Zones to Business Mobile Phones Shopping.
- BSet Dest Networks to Business Mobile Phones Shopping.
- CSet Time Range for rule 4 of Access Controlled Groups to All.
- DMove rule 4 Access Controlled Groups to the top.
How the community answered
(19 responses)- A11% (2)
- B5% (1)
- C5% (1)
- D79% (15)
Explanation
Option D is correct because Cisco Secure Firewall Management Center evaluates access control rules top-down, applying the first matching rule and ignoring the rest. If a broader "allow" rule appears above rule 4, it matches restricted users' traffic first and permits it before rule 4 ever gets evaluated - moving rule 4 to the top ensures the block fires first.
Why the distractors fail:
- A is wrong because "Business Mobile Phones Shopping" is a URL category, not a destination zone - destination zones refer to network interface segments (inside, outside, DMZ), not web content types.
- B is wrong for the same reason - destination networks are IP address ranges, not URL or application categories.
- C is wrong because changing the time range to "All" broadens when the rule applies but does nothing to fix the rule ordering problem; the rule still gets skipped if a higher rule already matches.
Memory tip: Think of FMC rules like a bouncer checklist - the first rule that matches "wins" and the rest are ignored. Whenever a block rule isn't working, ask "is something above it letting traffic through first?" - the fix is almost always order, not configuration of the rule itself.
Topics
Community Discussion
No community discussion yet for this question.
