nerdexam
Cisco

350-701 · Question #871

A network engineer must configure an access control policy on top of an existing Cisco Secure Firewall Threat Defense access control policy. The policy must contain IP addresses and port values with…

The correct answer is D. prefilter. A prefilter policy allows matching on IP addresses and ports with minimal processing, applied before deeper access control inspection, satisfying the requirement for simple, top-layer filtering.

Submitted by saadiq_pk· Mar 30, 2026

Question

A network engineer must configure an access control policy on top of an existing Cisco Secure Firewall Threat Defense access control policy. The policy must contain IP addresses and port values with no need for deeper inspection. Which type of policy must be created?

Options

  • ASSL
  • Bidentity
  • Caccess control
  • Dprefilter

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    5% (2)
  • D
    86% (38)

Explanation

A prefilter policy allows matching on IP addresses and ports with minimal processing, applied before deeper access control inspection, satisfying the requirement for simple, top-layer filtering.

Topics

#Cisco FTD#FTD Access Control#Prefilter Policy#Network Filtering

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice