exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 113 discussion

Actual exam question from Cisco's 350-701
Question #: 113
Topic #: 1
[All 350-701 Questions]

A Cisco FirePower administrator needs to configure a rule to allow a new application that has never been seen on the network. Which two actions should be selected to allow the traffic to pass without inspection? (Choose two.)

  • A. permit
  • B. allow
  • C. reset
  • D. trust
  • E. monitor
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rad9899
Highly Voted 3 years, 11 months ago
D. trust E. monitor
upvoted 30 times
loiphin
3 years, 4 months ago
In case you are still nervy about the above answers, then this diagram will calm your nerves :) https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/access_control_rules.html#ID-2190-00000005
upvoted 11 times
Fugashi
2 years, 11 months ago
https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/access_control_rules.html?bookSearch=true#ID-2190-0000023b There is an exception, however. If a Monitor rule contains layer 7 conditions—such as an application condition—the system allows early packets to pass and the connection to be established (or the SSL handshake to complete)
upvoted 3 times
...
...
...
west33637
Highly Voted 2 years, 3 months ago
Selected Answer: DE
create a monitor rule that matches the application. Then create a trust rule right below it.
upvoted 6 times
...
DANT7
Most Recent 2 days, 12 hours ago
Selected Answer: DE
In Cisco Firepower, "allow" passes traffic but still inspects it. "Trust" passes traffic without inspection. Since the question asks for allowing traffic without inspection, the correct answers are D. trust and E. monitor.
upvoted 1 times
...
Diegosuarezb
2 weeks, 3 days ago
Selected Answer: BD
B & D makes more sense to me
upvoted 1 times
...
Basuso
5 months, 2 weeks ago
Selected Answer: DE
It's Trust & Monitor. Trust applies fast-path to traffic, and Monitor only Logs the traffic. Allow will inspect traffic.
upvoted 2 times
...
mhd96far
1 year, 1 month ago
Selected Answer: DE
never seen on the network
upvoted 1 times
...
Pakawat
1 year, 4 months ago
Selected Answer: DE
Trust and Monitor
upvoted 1 times
...
xziomal9
1 year, 5 months ago
Answer DE
upvoted 1 times
...
HOUSSE
1 year, 6 months ago
TRUST AND MONITOR ALLOW IS NOT A GOOD ANSWER BECAUSE TRAFFIC WILL PASS UNDER INSPECTION
upvoted 1 times
...
Pakawat
1 year, 7 months ago
Selected Answer: DE
Trust and Monitor as the question mention that "without inspection".
upvoted 1 times
...
F0rtyx40
1 year, 9 months ago
D and E , allow rules are still subject to L7 processing
upvoted 1 times
...
bobie
1 year, 11 months ago
Selected Answer: BD
The allow action, If it does only file inspection, intrusion inspection, or neither, it signifies that it will not be inspected because the application is unknown. Without a doubt, the trust action is one of the proper answers.
upvoted 2 times
...
YooAndI
1 year, 12 months ago
Step 1: Monitor Step 2: Trust --> No inspection --> Reaches Destination Allow is further down on the process, Step 4, after Step 3: Block.
upvoted 2 times
...
psuoh
2 years, 3 months ago
The system does not perform deep inspection on trusted, blocked, or encrypted traffic. You monitor to log the session to use when "configuring a rule to allow a new application..."
upvoted 2 times
...
Emlia1
2 years, 4 months ago
D, E Explanation Each rule also has an action, which determines whether you monitor, trust, block, or allow matching traffic. Note: With action “trust”, Firepower does not do any more inspection on the traffic. There will be no intrusion protection and also no file-policy on this traffic.
upvoted 1 times
...
dique
2 years, 9 months ago
D and E (Trust and monitor.)
upvoted 1 times
...
otzu1
3 years ago
D/E https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/access_control_rules.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago