exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 60 discussion

Actual exam question from Cisco's 300-710
Question #: 60
Topic #: 1
[All 300-710 Questions]

An organization wants to secure traffic from their branch office to the headquarters building using Cisco Firepower devices. They want to ensure that their Cisco
Firepower devices are not wasting resources on inspecting the VPN traffic. What must be done to meet these requirements?

  • A. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic.
  • B. Tune the intrusion policies in order to allow the VPN traffic through without inspection.
  • C. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies.
  • D. Enable a flexconfig policy to re-classify VPN traffic so that it no longer appears as interesting traffic.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
14a1949
1 week, 1 day ago
Selected Answer: C
the correct answer is C. Configure the Cisco Firepower devices to ignore the VPN traffic using prefilter policies. Prefilter policies are specifically designed to handle scenarios like this, where you want to bypass deeper inspection for certain types of traffic, such as VPN traffic, to conserve resources. Option A, configuring the devices to bypass access control policies for VPN traffic, would not achieve the same result because access control policies are not designed to handle the bypassing of inspection processes in the same way prefilter policies do.
upvoted 1 times
...
gwb
5 months ago
key "not wasting resources on inspecting the VPN traffic" prefilter is right before ACP, thus to save resources, prefilter is much effective although ACP is doing same but happens after prefilter. 5-Tuple ACL -- prefilter is recommended by Cisco. google 5 tuple with prefilter.
upvoted 2 times
...
gc999
1 year ago
Selected Answer: A
Option C will be correct IF Site-to-site VPN traffic that is going through the device. That is, the device is not an endpoint in the VPN topology. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/access-prefilter.html#id_23357:~:text=Site%2Dto%2Dsite%20VPN%20traffic%20that%20is%20going%20through%20the%20device.%20That%20is%2C%20the%20device%20is%20not%20an%20endpoint%20in%20the%20VPN%20topology. Flows cannot be offloaded if IPsec and TLS/DTLS VPN connections that terminate on the device https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/access-prefilter.html#id_23357:~:text=IPsec%20and%20TLS/DTLS%20VPN%20connections%20that%20terminate%20on%20the%20device So I will choose A which is the easiest way to bypass VPN traffic for inspection.
upvoted 1 times
gc999
1 year ago
After reviewing all the materials, I would choose C now.
upvoted 1 times
...
...
greeklover84
1 year ago
Selected Answer: A
I would choose A
upvoted 1 times
...
ureis
1 year, 2 months ago
Just configure ACP to "Trust" and the traffic will not be inspected
upvoted 2 times
...
Joe_Blue
1 year, 4 months ago
Selected Answer: A
A. Configure the Cisco Firepower devices to bypass the access control policies for VPN traffic. By configuring the Cisco Firepower devices to bypass the access control policies for VPN traffic, the devices will not perform security inspection on the VPN traffic, which will help to conserve resources. This can be done by creating an access control rule that matches the VPN traffic and then setting the action to "Trust". This will allow the traffic to bypass the access control policies and not consume resources.
upvoted 2 times
...
aadach
2 years, 5 months ago
A : inside VPN S2S config (tunnel) can you find option "Access Control for VPN Traffic" - Bypass Access Control policy for decrypted traffic (sysopt permit-vpn), that is it !!
upvoted 3 times
...
ThanosAth
2 years, 6 months ago
A is correct answer. Check the following article. https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/prefiltering_and_prefilter_policies.html#id_31063 According to the article there are limitations to what type of traffic can be offloaded to fastpath. In the above article it is stated that "IPsec and TLS/DTLS VPN connections that terminate on the device" cannot be offloaded.
upvoted 2 times
...
4study
2 years, 8 months ago
I agree with C. Prefilter policies fit what is asked better I think
upvoted 2 times
...
Sarbi
2 years, 9 months ago
C is more appreciate an answer
upvoted 1 times
...
netwguy
2 years, 10 months ago
Its either A or C - im going for C. The problem with A is that if we bypass ACPs, then we not only bypass inspection, but also "ACL" control of traffic - entire encryption domains will be allowed. My problem with C is the use of the word "ignore". We do not want to "ignore" the VPN traffic, we just want to pass it though without inspection. C seems to be more correct - im guessing "ignore" is supposed to mean "ignore inspection" - terrible phrasing once more from Cisco.
upvoted 2 times
Weyland
1 year, 8 months ago
VPN Filter ACL and authorization ACL downloaded from aaa server are still applied if we bypass access control. And Prefilter cannot offload IPsec.
upvoted 1 times
...
...
cryptofetti
2 years, 10 months ago
Could be A or C. 50/50 chance here
upvoted 1 times
cryptofetti
2 years, 10 months ago
Leaning more towards C, since you can create a prefilter and fastpath VPN traffic
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago