350-201 · Question #39
Refer to the exhibit. What is the connection status of the ICMP event?
The correct answer is B. allowed by a configured access policy rule. This question tests how to interpret connection event data in Cisco FMC, specifically identifying the disposition and reason for an ICMP connection.
Question
Refer to the exhibit. What is the connection status of the ICMP event?
Exhibit
Options
- Ablocked by a configured access policy rule
- Ballowed by a configured access policy rule
- Cblocked by an intrusion policy rule
- Dallowed in the default action
How the community answered
(34 responses)- A3% (1)
- B91% (31)
- C6% (2)
Why each option
This question tests how to interpret connection event data in Cisco FMC, specifically identifying the disposition and reason for an ICMP connection.
Blocked by an access policy rule would show a 'Block' action in the connection event, not an allow disposition.
In Cisco FMC connection events, the 'Action' or 'Reason' field indicates why a connection was permitted or denied. When the event shows 'Allow' and references a specific access control policy rule name rather than the default action, it means a configured rule explicitly matched and permitted the traffic. This distinguishes a rule-based allow from the default action fallback.
Blocked by an intrusion policy rule would show an 'Intrusion Block' or 'IPS Block' reason, which is separate from access policy rule actions.
Allowed by the default action would not reference a named access control rule - it would show 'Default Action' as the reason, not a specific rule match.
Concept tested: Cisco FMC connection event interpretation and disposition
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/connection_and_security_intelligence_event_fields.html
Topics
Community Discussion
No community discussion yet for this question.
