nerdexam
Cisco

350-501 · Question #179

Refer to me exhibit. A network operator recently configured BGP FlowSpec for me internal IT network. What will be inferred from the configuration deployed on me network?

The correct answer is A. The policy is configured locally on CSRl and drops all traffic for TCP ports 80 and 443. The configuration on CSR1 is locally defined to drop TCP traffic destined for ports 80 and 443, indicating a direct application of a FlowSpec rule on that device rather than one learned from a BGP peer.

Networking

Question

Refer to me exhibit. A network operator recently configured BGP FlowSpec for me internal IT network. What will be inferred from the configuration deployed on me network?

Exhibit

350-501 question #179 exhibit

Options

  • AThe policy is configured locally on CSRl and drops all traffic for TCP ports 80 and 443
  • BThe policy is learned via BGP FlowSpec and drops all traffic for TCP ports 80 and 443
  • CThe policy is warned via BC FlowSpec aid has active traffic
  • DThe policy is configured locally on CSR1 and currently has no active traffic

How the community answered

(60 responses)
  • A
    73% (44)
  • B
    8% (5)
  • C
    3% (2)
  • D
    15% (9)

Why each option

The configuration on CSR1 is locally defined to drop TCP traffic destined for ports 80 and 443, indicating a direct application of a FlowSpec rule on that device rather than one learned from a BGP peer.

AThe policy is configured locally on CSRl and drops all traffic for TCP ports 80 and 443Correct

If the policy is configured locally on CSR1, it directly applies the specified action to traffic passing through that router. The action to drop traffic for TCP ports 80 and 443 is a common use case for BGP FlowSpec to mitigate specific traffic types.

BThe policy is learned via BGP FlowSpec and drops all traffic for TCP ports 80 and 443

If the policy were 'learned via BGP FlowSpec', it would be received from a BGP peer and installed, rather than being directly configured on CSR1, which is a key distinction for FlowSpec policy deployment.

CThe policy is warned via BC FlowSpec aid has active traffic

The phrase 'warned via BC FlowSpec aid has active traffic' contains grammatical errors and 'active traffic' does not provide sufficient information to infer the policy's origin or specific action.

DThe policy is configured locally on CSR1 and currently has no active traffic

While a locally configured policy might exist without active traffic, the core inference of the policy is its intended action of dropping traffic for specific ports, not the current state of traffic flow.

Concept tested: BGP FlowSpec local vs. learned policy application

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_bgp/configuration/xe-16/irg-xe-16-book/bgp-flowspec.html

Topics

#BGP FlowSpec#Network Security#CLI Interpretation#Routing Policies

Community Discussion

No community discussion yet for this question.

Full 350-501 Practice