hardMultiple ChoiceObjective-mapped
350-701 Practice Question: A company uses Microsoft Azure and has deployed…
A company uses Microsoft Azure and has deployed Cisco CloudCenter for workload lifecycle management. They also use Cisco Firepower NGFW in Azure. A security analyst notices that the Firepower logs show outbound connections from a workload to an IP address in a known threat feed. The workload is a Linux server that runs a custom application. The analyst checks Azure Network Security Groups (NSGs) and finds that outbound traffic is not restricted. The company's policy requires that all outbound traffic be inspected and logged. The analyst wants to block the specific IP while allowing other outbound traffic. Which action should be taken?
⚠ Common exam trap
Cisco often tests the misconception that Azure NSGs can replace a dedicated firewall for outbound traffic inspection and logging, but NSGs lack application-layer visibility and cannot enforce granular threat-feed-based blocking while maintaining required logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Firepower Access Control policy rule to block traffic to the threat IP and log it.
Cisco Firepower NGFW is the inline security enforcement point in this Azure deployment, and it can inspect and log all outbound traffic. Creating a Firepower Access Control policy rule to block the specific threat IP and log it directly enforces the security policy at the firewall layer, which is the only device capable of deep packet inspection and logging as required by company policy. NSGs operate at Layer 3/4 and cannot inspect application-layer traffic or integrate with threat feeds for granular IP blocking without affecting other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the NSG to deny all outbound traffic and then add allow rules for known good destinations.
Why it's wrong here
Incorrect: This will block many legitimate connections and require constant updates.
- ✓
Create a Firepower Access Control policy rule to block traffic to the threat IP and log it.
Why this is correct
Correct: Firepower can use dynamic threat intelligence to block.
- ✗
Add a network security group rule to block the specific IP address.
Why it's wrong here
Incorrect: NSGs are static and not integrated with threat feeds.
- ✗
Modify the route table to send all outbound traffic through a firewall, bypassing the NSG.
Why it's wrong here
Incorrect: This does not block the IP but adds latency.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.