exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 167 discussion

Actual exam question from Cisco's 300-710
Question #: 167
Topic #: 1
[All 300-710 Questions]

An engineer must define a URL object on Cisco FMC. What is the correct method to specify the URL without performing SSL inspection?

  • A. Include all URLs from CRL Distribution Points.
  • B. Use Subject Common Name value.
  • C. Specify all subdomains in the object group.
  • D. Specify the protocol in the object.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Stevens0103
8 months, 3 weeks ago
Selected Answer: B
The subject common name from the website certificate is used to match HTTPS traffic without performing SSL inspection. This allows the system to identify and match the URLs without decrypting the traffic, hence avoiding SSL inspection.
upvoted 4 times
...
THEODORABLE
1 year, 5 months ago
B: use the CN
upvoted 1 times
...
Initial14
1 year, 7 months ago
Selected Answer: B
B. In SSL policy you can block on CN before you decrypt traffic, this is also recommended by Cisco, because SSL decryption adds overhead.
upvoted 2 times
...
Initial14
1 year, 7 months ago
You can use URL filtering regarding CN, otherwise URL filtering would not work at all because URL that you are visiting in in HTTP header and that header is encrypted in SSL. There is also option in advance settings regarding decrypting TLS 1.3 so you can get Cn of server
upvoted 1 times
...
Joe_Blue
1 year, 8 months ago
Selected Answer: D
D. Specify the protocol in the object. To define a URL object on Cisco FMC without performing SSL inspection, the engineer can simply specify the protocol used by the URL, which is typically "http://" or "https://". By specifying the protocol in the object, the Cisco FMC will not attempt to perform SSL inspection on the URL. Option D is therefore the correct answer. The engineer should specify the protocol in the object to define a URL object on Cisco FMC without performing SSL inspection. The other options are not relevant to this task.
upvoted 3 times
...
tanri04
1 year, 8 months ago
Answer:C The correct method to specify the URL without performing SSL inspection is to specify the protocol in the object, which is option C. This can be done by selecting "http" or "https" from the Protocol drop-down menu in the Add URL Object window in Cisco FMC. By doing so, the FMC will create a URL object that matches only the specified protocol and will not inspect SSL traffic. Options A, B, and D are not relevant to this task.
upvoted 1 times
...
matan24
1 year, 8 months ago
Selected Answer: B
B is the answer. "HTTPS filtering, unlike HTTP filtering, disregards subdomains within the subject common name. Do not include subdomain information when manually filtering HTTPS URLs" https://www.cisco.com/c/en/us/td/docs/security/firepower/670/fdm/fptd-fdm-config-guide-670/fptd-fdm-access.html
upvoted 2 times
...
Mevijil
1 year, 9 months ago
Selected Answer: B
The Correct answer is B: If you plan to use a URL object to match HTTPS traffic in an access control rule, create the object using the subject common name in the public key certificate used to encrypt the traffic. Also, the system disregards subdomains within the subject common name, so do not include subdomain information. For example, use example.com rather than www.example.com. https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/reusable_objects.html#ID-2243-00000414
upvoted 1 times
Baumb
1 year, 9 months ago
Since it specifically states without SSL decryption, you cant use the subject common name. So I think the given answer is correct
upvoted 1 times
freho
1 year, 9 months ago
No, Mevijil is correct: You don´t need to decrypt anything to read the Certificates CN field.... B is correct.
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago