nerdexam
Cisco

350-201 · Question #39

Refer to the exhibit. What is the connection status of the ICMP event?

The correct answer is B. allowed by a configured access policy rule. This question tests how to interpret connection event data in Cisco FMC, specifically identifying the disposition and reason for an ICMP connection.

Network Intrusion Analysis

Question

Refer to the exhibit. What is the connection status of the ICMP event?

Exhibit

350-201 question #39 exhibit

Options

  • Ablocked by a configured access policy rule
  • Ballowed by a configured access policy rule
  • Cblocked by an intrusion policy rule
  • Dallowed in the default action

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    91% (31)
  • C
    6% (2)

Why each option

This question tests how to interpret connection event data in Cisco FMC, specifically identifying the disposition and reason for an ICMP connection.

Ablocked by a configured access policy rule

Blocked by an access policy rule would show a 'Block' action in the connection event, not an allow disposition.

Ballowed by a configured access policy ruleCorrect

In Cisco FMC connection events, the 'Action' or 'Reason' field indicates why a connection was permitted or denied. When the event shows 'Allow' and references a specific access control policy rule name rather than the default action, it means a configured rule explicitly matched and permitted the traffic. This distinguishes a rule-based allow from the default action fallback.

Cblocked by an intrusion policy rule

Blocked by an intrusion policy rule would show an 'Intrusion Block' or 'IPS Block' reason, which is separate from access policy rule actions.

Dallowed in the default action

Allowed by the default action would not reference a named access control rule - it would show 'Default Action' as the reason, not a specific rule match.

Concept tested: Cisco FMC connection event interpretation and disposition

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/connection_and_security_intelligence_event_fields.html

Topics

#ICMP#access policy rules#intrusion detection#firewall policy

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice