exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 227 discussion

Actual exam question from Cisco's 300-710
Question #: 227
Topic #: 1
[All 300-710 Questions]

A network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication. The Cisco FMC can connect to the LDAPS server, but the Cisco FTD is not connecting. Which configuration must be enabled on the Cisco FTD?

  • A. The LDAPS must be allowed through the access control policy.
  • B. The RADIUS server must be defined.
  • C. SSL must be set to a use TLSv1.2 or lower.
  • D. DNS servers must be defined for name resolution.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
THEODORABLE
1 year, 5 months ago
D- https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215538-configure-firepower-management-center-an.html see: 3. SSL or TLS does not work as expected If you don't enable DNS on the FTDs, you can see errors in the pigtail log that suggest that LDAP is unreachable:
upvoted 4 times
...
Initial14
1 year, 6 months ago
Selected Answer: D
A DNS record for the AD server is required because LDAPS clients typically use DNS to locate the domain controller hosting the AD server. The DNS record for the AD server helps clients resolve the server's hostname to its IP address.
upvoted 4 times
...
Joe_Blue
1 year, 7 months ago
Selected Answer: A
The correct answer is A. The LDAPS protocol is used for secure communication with an LDAP directory using SSL/TLS encryption. When the network administrator has converted a Cisco FTD from using LDAP to LDAPS for VPN authentication, the LDAPS protocol must be allowed through the access control policy. This means that the firewall rule on the Cisco FTD must allow traffic on the LDAPS port (usually 636/tcp) from the VPN clients to the LDAPS server. Option D (DNS servers must be defined for name resolution) is not correct because although DNS is important for name resolution, it is not directly related to LDAPS authentication.
upvoted 3 times
gwb
7 months, 3 weeks ago
Remote VPN is NOT under ACP. There is a separated section for RA VPN. I am going with DNS server
upvoted 1 times
...
...
Joe_Blue
1 year, 8 months ago
Selected Answer: D
It's possible that DNS servers must be defined for name resolution if the LDAPS server's hostname or IP address cannot be resolved by the Cisco FTD.
upvoted 2 times
...
freho
1 year, 8 months ago
Selected Answer: D
LDAPS means certificates has to be checked, for that we need the DNS
upvoted 2 times
...
Baumb
1 year, 8 months ago
Selected Answer: D
I would vote D according to this thread: https://community.cisco.com/t5/network-access-control/cisco-ftd-ldaps/td-p/4541263
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago