exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 106 discussion

Actual exam question from Cisco's 350-701
Question #: 106
Topic #: 1
[All 350-701 Questions]

An organization is trying to improve their Defense in Depth by blocking malicious destinations prior to a connection being established. The solution must be able to block certain applications from being used within the network. Which product should be used to accomplish this goal?

  • A. Cisco Firepower
  • B. Cisco Umbrella
  • C. Cisco ISE
  • D. Cisco AMP
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aaInman
Highly Voted 3 years, 10 months ago
Answer = B I work with Umbrella and Firepower daily. You can do this with Firepower, Umbrella whole existence is for blocking DNS connections to malicious sites before they are made, and blocking applications from launching on the internal network. For example, our users can't access Pandora, FB, Google Docs while on our internal network based on a policy configured in Umbrella.
upvoted 17 times
...
AS04
Highly Voted 3 years, 8 months ago
A is correct, Firepower has AVC feature that can block traffic based on application.
upvoted 7 times
west33637
2 years, 4 months ago
B is correct. AVC on Firepower can not block applications from being used within the network. Firepower can only block these applications if they pass through the firewall. Umbrella can block connections to malicious sites before the connection is made based on the DNS lookup. Umbrella also installs an endpoint supplicant or can be used as an Anyconnect module. This way you can push an application policy to the endpoints blocking even applications 'within the network'. Same as aalnman, I have used this at work and at home.
upvoted 7 times
...
...
ITPro21
Most Recent 3 weeks ago
Selected Answer: B
Acts as a first line of defense, blocking threats before they reach the network or endpoints.
upvoted 1 times
...
kloug
6 months, 1 week ago
Answer b
upvoted 1 times
...
luismg
7 months, 2 weeks ago
Selected Answer: D
I would say is D Umbrella cannot stop ip connections firepower just traffic that goes through it. amp is host ralated, it can block any connection
upvoted 1 times
...
Premium_Pils
9 months ago
Selected Answer: B
Block the process right at the beginning, i.e. at the DNS request step, before making a connection to the bad website. - B
upvoted 1 times
Premium_Pils
7 months ago
https://umbrella.cisco.com/products/sig-product The question would fit for umbrella, except that it is about blocking access within the network. (However, they did not specify which network.) Did someone find a relevant documentation about AMP?
upvoted 1 times
Premium_Pils
7 months ago
Block from being used within the network... So, the application could reside on the internet, but being inaccessible in the organisation network. I think, it is what umbrella does.
upvoted 1 times
...
...
...
4pelos
1 year, 2 months ago
Correct answer B. Checked in securitytut
upvoted 2 times
...
xziomal9
1 year, 6 months ago
Answer B
upvoted 1 times
...
jorg32
1 year, 9 months ago
Selected Answer: B
Umbrella, is trying to block the start of the conversation with bad websites, why block the application when you know you can block way earlier on the traffic flow?
upvoted 1 times
...
Jessie45785
1 year, 10 months ago
Selected Answer: D
The solution must be able to block certain applications from being used within the network I really think it is D cause: - NGFW cannot stop it in L2 - Umbrella can block only DNS protocol - what about all the other ones - wont be able to detect it - WSA - proxy will definitely will not help here ... but AMP can block application from being able to start hence cutting it from TCP stack and fulfilling a requirement of "blocking malicious destinations prior to a connection being established" but it is Cisco so you never know :/
upvoted 2 times
...
F0rtyx40
1 year, 11 months ago
It's B, Umbrella can block the connection before firepower L7 application detectors kick in.
upvoted 1 times
...
gc999
1 year, 11 months ago
I think most of us already get the keywords here "prior to a connection being established" and "within the network". Can I make an example that if there are two internal users, let say User-1 and User-2, within the network, which solution can block the certain application being send from User-1 to User-2?
upvoted 1 times
...
This is a tricky one, the question is weird because the keywords are "prior to a connection being established" and "must be able to block certain applications". It is true that Umbrella blocks the DNS traffic so that it does that take care of "prior to a connection being established". However, Umbrella does not block the application itself just the DNS traffic, so if the application does not utilize DNS and is IP based, it will not block anything, Firepower on the other hand can block the applications and with a "Block with Reset" it does not allow any connection to be established. Also, both can block based on malicious destination. I will still go with B though.
upvoted 1 times
...
KPzee
2 years, 1 month ago
A is correct a firewall will block certain applications that might already be on the network.
upvoted 1 times
...
Toni_Su91
2 years, 1 month ago
Prior to a connection being established - This is classic Umbrella - DNS security is first line of defence.
upvoted 2 times
...
sull3y
2 years, 3 months ago
The answer is B. Cisco Umbrella. Cisco Umbrella is a cloud-based security solution that provides advanced threat protection and blocks malicious destinations before a connection is established. It uses DNS-layer security to block requests to known malicious domains and IPs, and it also has the capability to block certain applications from being used within the network. By implementing Cisco Umbrella, the organization can improve their defense in depth by preventing malicious traffic from entering the network, thus reducing the risk of a successful cyber attack.
upvoted 3 times
...
psuoh
2 years, 3 months ago
I think A is the Cisco's correct answer. the question asks "within the network". Umbrella would do on and off the network/app blocking. Similarily, firepower can do network/app block for the network. Umbrella would be a overkill for a "organization". https://community.cisco.com/t5/network-security/firepower-or-umbrella-for-blocking-urls-applications-ip/td-p/4430076
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago