exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 235 discussion

Actual exam question from Cisco's 300-710
Question #: 235
Topic #: 1
[All 300-710 Questions]

An engineer defines a new rule while configuring an Access Control Policy. After deploying the policy, the rule is not working as expected and the hit counters associated with the rule are showing zero. What is causing this error?

  • A. An incorrect application signature was used in the rule.
  • B. The wrong source interface for Snort was selected in the rule.
  • C. The rule was not enabled after being created.
  • D. Logging is not enabled for the rule.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pata311
2 days, 21 hours ago
Selected Answer: C
I would say C because of this: The policy hit count is incremented only for the first packet of a connection that matches a policy. https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_access_control_policies.html An application takes more than the first packet to be identified, so this is only based on source/dest IP, ports and protocol. Even if the application was incorrect, it would increase hits based on this.
upvoted 1 times
...
eafea4f
6 months ago
Selected Answer: A
I changed my answer to A. New new rules in 7.3 are enabled by default.
upvoted 1 times
...
z6st2a1jv
1 year, 2 months ago
Selected Answer: A
When you create an access control rule, it is enabled by default. https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/access_control_rules.html
upvoted 3 times
...
bassfunk
1 year, 5 months ago
Selected Answer: C
Honestly the answer could be A or C. C requires the least assumptions so it sounds better.
upvoted 3 times
...
Initial14
1 year, 9 months ago
Selected Answer: A
Only A. Incorrect Application signature: Lets say you want to block facebook, and instead facebook you used Facebook games. B and D makes no sense C: Rules are enabled by default, only SNORT rules need to be enabled (drop and generate events, generate events,...) to take action.
upvoted 3 times
gwb
10 months ago
good explanation!
upvoted 1 times
...
...
Joe_Blue
1 year, 10 months ago
Selected Answer: C
The correct answer is C. The most likely cause of the error is that the rule was not enabled after being created. By default, new rules are created in a disabled state, which means that they do not take effect until they are explicitly enabled. If the rule is not enabled, it will not be matched against traffic and the hit counters associated with the rule will remain at zero.
upvoted 2 times
Initial14
1 year, 9 months ago
What ? When you create ACL rule you do no ned to enable it ?!. If there is no hits in counter, that means the traffic did not match the criteria: source IP, destination IP, URL, application,... So C is not the one. I think you are refering to SNORT rules and that is not the case here
upvoted 1 times
Bbb78
1 year, 7 months ago
You dont need to enable it - but if it is not enabled the hitcnt will be ). Still it could be A ....so
upvoted 1 times
...
...
never1
1 year, 7 months ago
Joe, i have just checked the new rules are not created in a disabled state (at least in my case). I still go with answer C because of hit count.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago