nerdexam
Cisco

350-701 · Question #443

An organization must add new firewalls to its infrastructure and wants to use Cisco ASA or Cisco FTD. The chosen firewalls must provide methods of blocking traffic that include offering the user the…

The correct answer is C. Cisco FTD because it enables interactive blocking and blocking with reset natively, whereas. Cisco Firepower Threat Defense (FTD) offers native capabilities for interactive blocking with user bypass options and connection resets, which are advanced features typically found in next-generation firewalls, making it the suitable choice over Cisco ASA for this requirement.

Submitted by layla.eg· Mar 30, 2026Network Security

Question

An organization must add new firewalls to its infrastructure and wants to use Cisco ASA or Cisco FTD. The chosen firewalls must provide methods of blocking traffic that include offering the user the option to bypass the block for certain sites after displaying a warning page and to reset the connection. Which solution should the organization choose?

Options

  • ACisco FTD because it supports system rate level traffic blocking, whereas Cisco ASA does not
  • BCisco ASA because it allows for interactive blocking and blocking with reset to be configured via
  • CCisco FTD because it enables interactive blocking and blocking with reset natively, whereas
  • DCisco ASA because it has an additional module that can be installed to provide multiple blocking

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    76% (22)
  • D
    14% (4)

Why each option

Cisco Firepower Threat Defense (FTD) offers native capabilities for interactive blocking with user bypass options and connection resets, which are advanced features typically found in next-generation firewalls, making it the suitable choice over Cisco ASA for this requirement.

ACisco FTD because it supports system rate level traffic blocking, whereas Cisco ASA does not

Both FTD and ASA have mechanisms for rate-limiting or blocking based on traffic patterns, but this is not the specific, interactive blocking feature described in the question.

BCisco ASA because it allows for interactive blocking and blocking with reset to be configured via

Cisco ASA does not natively provide the interactive blocking with user bypass or warning pages described; its blocking is generally a hard block.

CCisco FTD because it enables interactive blocking and blocking with reset natively, whereasCorrect

Cisco FTD (Firepower Threat Defense), as a next-generation firewall (NGFW), provides advanced application control and URL filtering capabilities that include features like interactive blocking (displaying a warning page with an option to bypass) and blocking with reset for specific traffic or applications. These granular and user-interactive blocking methods are inherent to FTD's deeper inspection capabilities, whereas Cisco ASA, a traditional firewall, primarily offers simpler block/allow actions without such interactive options natively.

DCisco ASA because it has an additional module that can be installed to provide multiple blocking

While ASA can be augmented with modules, the advanced interactive blocking described is a core FTD feature rather than an ASA module capability.

Concept tested: Cisco FTD advanced blocking features vs. ASA

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/url_filtering_and_application_control.html

Topics

#Cisco FTD#Cisco ASA#interactive blocking#block with reset

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice