Refer to the exhibit. An engineer must block FTP traffic coming in from a particular Service VPN on a WAN Edge device. Which set of steps achieves this goal?
A.
Create a localized policy and add it to the interface feature template.
B.
Create a localized policy, add it to VPN template, and add an ACL to the interface feature template.
C.
Create a prefix list, add it to the localized policy, and add it to the interface feature template.
D.
Create a localized policy, add it to the device template, and add an ACL to the interface feature template.
C. local umbrella agent
Explanation:
The local umbrella agent is the feature that delivers traffic from a Cisco SD-WAN domain to the Cisco Umbrella Secure Internet Gateway (SIG) cloud. The local umbrella agent is a software agent that runs on the WAN Edge routers within the SD-WAN domain.
When traffic passes through the WAN Edge routers, the local umbrella agent redirects the DNS traffic to the Cisco Umbrella SIG cloud for inspection and security enforcement. This integration enables the enforcement of security policies, such as content filtering and blocking malicious domains, at the DNS level.
Option A (L2TPv3 tunnel) and Option B (IPsec tunnel) are VPN tunneling technologies and are not directly related to delivering traffic to the Cisco Umbrella SIG cloud.
Option D (source NAT) is a networking technique used for translating source IP addresses but is not specifically related to delivering traffic to the Cisco Umbrella SIG cloud.
The exhibit already shows a localized policy created in VManage, their is no need to create a new one. You only need to create an ACLthat block's FTP traffic (Port 20/21) ingress on an interface (in VManage add it to the localized, then interface feature)
Option [C] is the answer here.
Option D is the exact list of required steps that achieve the goal. The fact that one of these steps is already done in the exhibit doesn't matter. They often write questions that way, where you have to list all the steps, even the steps already done in the exhibit.
upvoted 3 times
...
...
This section is not available anymore. Please use the main Exam Page.300-415 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Rosh8787
6 months, 3 weeks agoabvga
1 year, 2 months agoZamochit
1 year, 3 months agosoltani
1 year, 3 months agotimtgh
1 year, 7 months agotimtgh
1 year, 7 months agocolipto
1 year, 9 months agocolipto
1 year, 9 months agocolipto
1 year, 9 months agoNetArch_Teck
1 year, 9 months agotimtgh
1 year, 7 months ago