exam questions

Exam 300-415 All Questions

View all questions & answers for the 300-415 exam

Exam 300-415 topic 1 question 288 discussion

Actual exam question from Cisco's 300-415
Question #: 288
Topic #: 1
[All 300-415 Questions]



Refer to the exhibit. An engineer must block FTP traffic coming in from a particular Service VPN on a WAN Edge device. Which set of steps achieves this goal?

  • A. Create a localized policy and add it to the interface feature template.
  • B. Create a localized policy, add it to VPN template, and add an ACL to the interface feature template.
  • C. Create a prefix list, add it to the localized policy, and add it to the interface feature template.
  • D. Create a localized policy, add it to the device template, and add an ACL to the interface feature template.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rosh8787
6 months, 3 weeks ago
Option D is the correct answer. We attach localized policy to the device template not while creating vpn template.
upvoted 1 times
...
abvga
1 year, 2 months ago
Selected Answer: D
added via device template.
upvoted 1 times
...
Zamochit
1 year, 3 months ago
I say A. Interface feature template permit to add a localized acl policy
upvoted 1 times
...
soltani
1 year, 3 months ago
B is wrong because a localized data policy apply to an interface not a VPN C is correct
upvoted 2 times
...
timtgh
1 year, 7 months ago
The only place you can apply a localized policy is to a device template. Not to any type of feature template.
upvoted 1 times
...
timtgh
1 year, 7 months ago
Option D is correct.
upvoted 3 times
...
colipto
1 year, 9 months ago
C. local umbrella agent Explanation: The local umbrella agent is the feature that delivers traffic from a Cisco SD-WAN domain to the Cisco Umbrella Secure Internet Gateway (SIG) cloud. The local umbrella agent is a software agent that runs on the WAN Edge routers within the SD-WAN domain. When traffic passes through the WAN Edge routers, the local umbrella agent redirects the DNS traffic to the Cisco Umbrella SIG cloud for inspection and security enforcement. This integration enables the enforcement of security policies, such as content filtering and blocking malicious domains, at the DNS level. Option A (L2TPv3 tunnel) and Option B (IPsec tunnel) are VPN tunneling technologies and are not directly related to delivering traffic to the Cisco Umbrella SIG cloud. Option D (source NAT) is a networking technique used for translating source IP addresses but is not specifically related to delivering traffic to the Cisco Umbrella SIG cloud.
upvoted 1 times
colipto
1 year, 9 months ago
This was posted to the wrong question
upvoted 1 times
colipto
1 year, 9 months ago
And it's also wrong
upvoted 1 times
...
...
...
NetArch_Teck
1 year, 9 months ago
The exhibit already shows a localized policy created in VManage, their is no need to create a new one. You only need to create an ACLthat block's FTP traffic (Port 20/21) ingress on an interface (in VManage add it to the localized, then interface feature) Option [C] is the answer here.
upvoted 4 times
timtgh
1 year, 7 months ago
Option D is the exact list of required steps that achieve the goal. The fact that one of these steps is already done in the exhibit doesn't matter. They often write questions that way, where you have to list all the steps, even the steps already done in the exhibit.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago