exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 235 discussion

Actual exam question from Cisco's 300-710
Question #: 235
Topic #: 1
[All 300-710 Questions]

An engineer defines a new rule while configuring an Access Control Policy. After deploying the policy, the rule is not working as expected and the hit counters associated with the rule are showing zero. What is causing this error?

  • A. An incorrect application signature was used in the rule.
  • B. The wrong source interface for Snort was selected in the rule.
  • C. The rule was not enabled after being created.
  • D. Logging is not enabled for the rule.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d0980cc
3 months ago
Selected Answer: D
If, "After deploying the policy, the rule is not working as expected", because the rule was not enabled, then C. If it's "not working as expected" because you selected the incorrect application signature, then A. If it's "not working as expected" because it's not logging, then D. I pray I don't encounter this vague question! I'll go with D, just to add to the turmoil.
upvoted 1 times
...
Pata311
5 months, 1 week ago
Selected Answer: C
I would say C because of this: The policy hit count is incremented only for the first packet of a connection that matches a policy. https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_access_control_policies.html An application takes more than the first packet to be identified, so this is only based on source/dest IP, ports and protocol. Even if the application was incorrect, it would increase hits based on this.
upvoted 1 times
Silexis
4 months, 1 week ago
When you add a rule in ACP, the default state is Enabled and I suspect the same is on most if not all firewalls from different vendors (Forti and Palo for sure). Logging might be a cause but the scenario says that also it is not functioning as expected - so it is not an issue related only to logs
upvoted 1 times
...
...
eafea4f
11 months, 1 week ago
Selected Answer: A
I changed my answer to A. New new rules in 7.3 are enabled by default.
upvoted 2 times
...
z6st2a1jv
1 year, 7 months ago
Selected Answer: A
When you create an access control rule, it is enabled by default. https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/access_control_rules.html
upvoted 3 times
...
bassfunk
1 year, 10 months ago
Selected Answer: C
Honestly the answer could be A or C. C requires the least assumptions so it sounds better.
upvoted 3 times
Nian
1 month, 3 weeks ago
I agree - Even if the signature was incorrect it would result in low matches or wrong matches, but not zero hit counters unless traffic is not using the app at all.
upvoted 1 times
...
...
Initial14
2 years, 2 months ago
Selected Answer: A
Only A. Incorrect Application signature: Lets say you want to block facebook, and instead facebook you used Facebook games. B and D makes no sense C: Rules are enabled by default, only SNORT rules need to be enabled (drop and generate events, generate events,...) to take action.
upvoted 3 times
gwb
1 year, 3 months ago
good explanation!
upvoted 1 times
...
...
Joe_Blue
2 years, 3 months ago
Selected Answer: C
The correct answer is C. The most likely cause of the error is that the rule was not enabled after being created. By default, new rules are created in a disabled state, which means that they do not take effect until they are explicitly enabled. If the rule is not enabled, it will not be matched against traffic and the hit counters associated with the rule will remain at zero.
upvoted 2 times
Initial14
2 years, 2 months ago
What ? When you create ACL rule you do no ned to enable it ?!. If there is no hits in counter, that means the traffic did not match the criteria: source IP, destination IP, URL, application,... So C is not the one. I think you are refering to SNORT rules and that is not the case here
upvoted 1 times
Bbb78
2 years ago
You dont need to enable it - but if it is not enabled the hitcnt will be ). Still it could be A ....so
upvoted 1 times
...
...
never1
2 years ago
Joe, i have just checked the new rules are not created in a disabled state (at least in my case). I still go with answer C because of hit count.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...