exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 125 discussion

Actual exam question from Cisco's 350-701
Question #: 125
Topic #: 1
[All 350-701 Questions]

An administrator is trying to determine which applications are being used in the network but does not want the network devices to send metadata to Cisco
Firepower. Which feature should be used to accomplish this?

  • A. Network Discovery
  • B. Access Control
  • C. Packet Tracer
  • D. NetFlow
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Raajaa
Highly Voted 3 years, 10 months ago
A is the answer as the Q specifies without using metadata
upvoted 8 times
...
Demon_Queen_Velverosa
Most Recent 7 months, 3 weeks ago
The Demon Queen sees you all are overthinking this XD. This question is to throw you off and took me time to get why its netflow and checked multiple sources. An administrator is trying to determine which applications are being used in the network but does not want the network devices to send metadata to Cisco Firepower. Which feature should be used to accomplish this? As in the question says we want to know what apps are being used on the network. However they throw you off by saying "but does not want the network devices to send metadata to Cisco Firepower.". Ask your self, Why do we care about Cisco FirePower in this question? We don't as we want to know what apps are on the network. By using netflow you have the network devices including firepower sending flow data out to be analyzed to other devices to analyze, but not sending data to the firepower device. They never said firepower could not be used as a sensor. The key word here is not "send" to firepower, but nothing about sending from firepower
upvoted 1 times
...
xziomal9
1 year, 6 months ago
Answer A
upvoted 1 times
...
KPzee
2 years, 1 month ago
It cannot be D as Netflow is concerned with metadata.
upvoted 2 times
...
Emlia1
2 years, 4 months ago
I prefer A
upvoted 1 times
...
sis_net_sec
2 years, 7 months ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Network_Discovery_Policies.html The network discovery policy has a single default rule in place, configured to discover applications from all observed traffic. The rule does not exclude any networks, zones, or ports, host and user discovery is not configured, and the rule is not configured to monitor a NetFlow exporter. This policy is deployed by default to any managed devices when they are registered to the Firepower Management Center. To begin collecting host or user data, you must add or modify discovery rules and re-deploy the policy to a device.
upvoted 2 times
...
francojaraba
2 years, 9 months ago
Selected Answer: A
As long the questions indicates that no metada is required the answer is A - https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/enterprise-network-security/white-paper-c11-736595.html Netflow are based on metadata - https://learning.oreilly.com/library/view/ccna-cyber-ops/9780134608938/ch04.html#ch04lev1sec1
upvoted 4 times
...
networkexpert
3 years ago
Selected Answer: A
I am eliminating D
upvoted 1 times
...
semi1750
3 years, 1 month ago
Selected Answer: A
Opt for A. Cisco doc says Applications can be discovered by "non-NetFlow discovery rules" without Option D You can disable detection of application protocols in discovery rules configured to monitor NetFlow exporters, but not in discovery rules configured to monitor Firepower System managed devices. If you enable host or user discovery in non-NetFlow discovery rules, applications are automatically discovered. https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/working_with_discovery_events.html
upvoted 3 times
...
pohqinan
3 years, 1 month ago
keyword network devices = switch / router therefore netflow. Network Discover usually is PC client send out
upvoted 2 times
NikoNiko
2 years, 9 months ago
"determine which applications" are running... and "does NOT want the network devices to send metadata to Cisco Firepower" Correct answer is Network Discovery - a Firepower feature, which fingerprints devices and applications in LAN by their communication parameters.
upvoted 2 times
...
...
Floki_viking7
3 years, 2 months ago
An Overview of the NetFlow Protocol: NetFlow is a protocol used to collect metadata on IP traffic flows traversing a network device. Developed by Cisco Systems, NetFlow is used to record metadata about IP traffic flows traversing a network device such as a router, switch, or host
upvoted 1 times
...
zheka
3 years, 5 months ago
Someone below gave an example that Netflow operates with metadata and if we don't want to send them to Cisco FMC then we need to select Netflow as the answer, simple as 123. And yes, you can discover applications by network discoveries by Firepower. Just checked in real production environment
upvoted 1 times
...
zeroC00L
3 years, 7 months ago
i would go with A here. Because the Network Discovery feature on the FMC/FTD/Firepower stuff works like a passive monitor. The Firewalls are looking into the traffic which is passing through them and use the information they get from there to build up host information you can view from within FMC. So there is no need to send (active do something) metadata the firewalls can get this passively by using network discovery policy.
upvoted 1 times
...
kapplejacks
3 years, 7 months ago
Correct answer is A: Question asks for "Firepower", I wish they would specify but I believe they are refering to ASA with firePOWER not FTD. If they say Firepower, cisco usually also includes Threat Defense so its for the ASA. The ASA does know about are on the network using network discovery and can be view in ASDM without (also a key, the question asks "but does not want to send metadata") so it has to be network discovery
upvoted 2 times
kapplejacks
3 years, 7 months ago
Also its called FireSight, it enables you to see HTTP related info or basically application traffic in a GUI connected to your ASA. FireSight.
upvoted 1 times
...
...
Sarbi
3 years, 8 months ago
I think the answer is A. As Netflow used metedata to analysise the flow. Rather than always relying on full packet capture, protocols like NetFlow and IPFIX can generate valuable metadata for less-intensive network monitoring. This metadata is similar to how your phone bill shows your calls, displaying the source, destination and volume rather than showing the actual content of the conversations. With this information, you can gain useful insights at a lower impact on your network management strategy. But which approach or metadata protocol is right for your network monitoring needs?
upvoted 1 times
...
kerniger
3 years, 8 months ago
I think A is not true because its based on metadata from firepower by default With NetFlow you can detect applications without metadata at firepower.
upvoted 1 times
...
zap_pap
3 years, 9 months ago
- A "The network discovery policy has a single default rule in place, configured to discover applications from all observed traffic." https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Network_Discovery_Policies.html
upvoted 3 times
Pwned
2 years, 11 months ago
This is correct!!
upvoted 1 times
Nian
1 month, 2 weeks ago
Yep.. "Discovery rules within the policy specify which networks and ports the Firepower System monitors to generate discovery data based on network data in traffic, and the zones to which the policy is deployed. Within a rule, you can configure whether hosts, applications, and non-authoritative users are discovered" https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Network_Discovery_Policies.html
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago