350-701 · Question #443
An organization must add new firewalls to its infrastructure and wants to use Cisco ASA or Cisco FTD. The chosen firewalls must provide methods of blocking traffic that include offering the user the…
The correct answer is C. Cisco FTD because it enables interactive blocking and blocking with reset natively, whereas. Cisco Firepower Threat Defense (FTD) offers native capabilities for interactive blocking with user bypass options and connection resets, which are advanced features typically found in next-generation firewalls, making it the suitable choice over Cisco ASA for this requirement.
Question
An organization must add new firewalls to its infrastructure and wants to use Cisco ASA or Cisco FTD. The chosen firewalls must provide methods of blocking traffic that include offering the user the option to bypass the block for certain sites after displaying a warning page and to reset the connection. Which solution should the organization choose?
Options
- ACisco FTD because it supports system rate level traffic blocking, whereas Cisco ASA does not
- BCisco ASA because it allows for interactive blocking and blocking with reset to be configured via
- CCisco FTD because it enables interactive blocking and blocking with reset natively, whereas
- DCisco ASA because it has an additional module that can be installed to provide multiple blocking
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- C76% (22)
- D14% (4)
Why each option
Cisco Firepower Threat Defense (FTD) offers native capabilities for interactive blocking with user bypass options and connection resets, which are advanced features typically found in next-generation firewalls, making it the suitable choice over Cisco ASA for this requirement.
Both FTD and ASA have mechanisms for rate-limiting or blocking based on traffic patterns, but this is not the specific, interactive blocking feature described in the question.
Cisco ASA does not natively provide the interactive blocking with user bypass or warning pages described; its blocking is generally a hard block.
Cisco FTD (Firepower Threat Defense), as a next-generation firewall (NGFW), provides advanced application control and URL filtering capabilities that include features like interactive blocking (displaying a warning page with an option to bypass) and blocking with reset for specific traffic or applications. These granular and user-interactive blocking methods are inherent to FTD's deeper inspection capabilities, whereas Cisco ASA, a traditional firewall, primarily offers simpler block/allow actions without such interactive options natively.
While ASA can be augmented with modules, the advanced interactive blocking described is a core FTD feature rather than an ASA module capability.
Concept tested: Cisco FTD advanced blocking features vs. ASA
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/url_filtering_and_application_control.html
Topics
Community Discussion
No community discussion yet for this question.