nerdexam
Cisco

350-701 · Question #566

Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZjnside zone once the configuration is deployed?

The correct answer is A. All traffic from any zone to the DMZ_inside zone will be permitted with no further inspection. A basic permit access control rule in Cisco FMC, without associated inspection policies, will allow all matching traffic to pass through to the DMZ_inside zone without further security inspection.

Submitted by the_admin· Mar 30, 2026

Question

Refer to the exhibit. When configuring this access control rule in Cisco FMC, what happens with the traffic destined to the DMZjnside zone once the configuration is deployed?

Exhibit

350-701 question #566 exhibit

Options

  • AAll traffic from any zone to the DMZ_inside zone will be permitted with no further inspection
  • BNo traffic will be allowed through to the DMZ_inside zone regardless of if it's trusted or not
  • CAll traffic from any zone will be allowed to the DMZ_inside zone only after inspection
  • DNo traffic will be allowed through to the DMZ_inside zone unless it's already trusted

How the community answered

(51 responses)
  • A
    82% (42)
  • B
    10% (5)
  • C
    6% (3)
  • D
    2% (1)

Why each option

A basic permit access control rule in Cisco FMC, without associated inspection policies, will allow all matching traffic to pass through to the DMZ_inside zone without further security inspection.

AAll traffic from any zone to the DMZ_inside zone will be permitted with no further inspectionCorrect

If an access control rule in Cisco FMC is configured with a simple 'permit' action without an associated intrusion policy, file policy, or other deep inspection profiles, then all traffic matching that rule (e.g., from any zone to DMZ_inside) will be allowed to pass through the firewall without further security inspection. This implies it bypasses advanced threat analysis capabilities.

BNo traffic will be allowed through to the DMZ_inside zone regardless of if it's trusted or not

A permit rule's purpose is to allow traffic, so stating 'no traffic will be allowed' contradicts the nature of a permit rule.

CAll traffic from any zone will be allowed to the DMZ_inside zone only after inspection

Traffic is only allowed after inspection if an inspection policy (like an intrusion policy or file policy) is explicitly applied to the access control rule. A basic permit rule does not imply inspection.

DNo traffic will be allowed through to the DMZ_inside zone unless it's already trusted

The concept of 'trusted' traffic is usually defined by policies or specific rules, and a general permit rule doesn't inherently imply a pre-existing trust; it simply permits what it matches.

Concept tested: Cisco FMC Access Control Rule behavior

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/access_control_policies_and_rules.html

Topics

#FMC Access Control#Security Policy#DMZ Network#Traffic Flow

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice