exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 261 discussion

Actual exam question from Cisco's 350-701
Question #: 261
Topic #: 1
[All 350-701 Questions]

An organization configures Cisco Umbrella to be used for its DNS services. The organization must be able to block traffic based on the subnet that the endpoint is on, but sees only the requests from its public IP addresses instead of each internal IP address. What must be done to resolve this issue?

  • A. Install the Microsoft Active Directory Connector to give IP address information stitched to the requests in the Cisco Umbrella dashboard.
  • B. Use the tenant control features to identify each subnet being used and track the connections within the Cisco Umbrella dashboard.
  • C. Configure an internal domain within Cisco Umbrella to help identify each address and create policy from the domains.
  • D. Set up a Cisco Umbrella virtual appliance to internally field the requests and see the traffic of each IP address.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
angry
Highly Voted 1 year, 1 month ago
Cisco is horrible in creating exam questions!
upvoted 13 times
...
Minion2021
Highly Voted 2 years, 1 month ago
The Answer is D
upvoted 6 times
Smileebloke
2 years ago
https://docs.umbrella.com/deployment-umbrella/docs/internal-networks-setup-guide
upvoted 2 times
...
...
fdl543
Most Recent 9 months ago
Selected Answer: D
D. Question says "based on the subnet that the endpoint is on". Nothing about Active Directory. Not all networks use AD...
upvoted 2 times
...
DWizard
9 months, 2 weeks ago
Selected Answer: D
The answer seems to be D, according to the link already provided: https://docs.umbrella.com/deployment-umbrella/docs/internal-networks-setup-guide The following link shows that the MS AD connector is intended to be used for a different purpose: https://docs.umbrella.com/umbrella-user-guide/docs/introduction-4
upvoted 2 times
...
mmpaing
10 months, 2 weeks ago
Selected Answer: A
The correct answer is A. Install the Microsoft Active Directory Connector to give IP address information stitched to the requests in the Cisco Umbrella dashboard. Cisco Umbrella uses the public IP address of the device to identify it. If the organization wants to block traffic based on the subnet that the endpoint is on, it needs to provide Cisco Umbrella with the internal IP address information. This can be done by installing the Microsoft Active Directory Connector (AD Connector) and configuring it to synchronize the organization's Active Directory with Cisco Umbrella. The AD Connector will synchronize the organization's Active Directory with Cisco Umbrella, which will allow Cisco Umbrella to see the internal IP address of the device. This will allow the organization to block traffic based on the subnet that the endpoint is on.
upvoted 1 times
...
sull3y
1 year, 2 months ago
D. Set up a Cisco Umbrella virtual appliance to internally field the requests and see the traffic of each IP address. When using Cisco Umbrella for DNS services, it can be challenging to track traffic based on subnets because the public IP addresses of the endpoint are seen instead of the internal IP addresses. To resolve this issue, an organization can set up a Cisco Umbrella virtual appliance to internally field the requests and see the traffic of each IP address. This will allow the organization to track traffic based on the subnet that the endpoint is on and implement policies to block traffic as needed. The virtual appliance acts as a proxy that fields the requests, enabling visibility into the internal IP addresses and allowing the organization to see the full picture of its network traffic.
upvoted 5 times
...
NikoNiko
1 year, 9 months ago
"How Umbrella Virtual Appliances Work VAs act as conditional DNS forwarders in your network, intelligently forwarding public DNS queries to Cisco Umbrella's global network, and local DNS queries to your existing local DNS servers and forwarders. Every public DNS query sent to Umbrella is encrypted, authenticated, and includes the client's internal IP address." <-- CLIENT'S INTERNAL IP ADDRESS. "VAs record the internal IP address of every DNS request. Security and DNS traffic-related investigations allow you to associate traffic to an individual, internal IP address." See picture here: https://docs.umbrella.com/deployment-umbrella/docs/1-introduction
upvoted 2 times
...
SanchezEldorado
2 years ago
Two links below show that it is NOT C and it IS D. C is for cloud to on prem, where the virtual appliance allows you to bypass NAT which is the crux of the question. https://docs.umbrella.com/deployment-umbrella/docs/internal-networks-setup-guide https://docs.umbrella.com/deployment-umbrella/docs/appx-d-internal-domains
upvoted 3 times
...
Cock
2 years, 3 months ago
c,c is the answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago