Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: Is using Cisco Firepower Threat Defense (FTD)…

An organization is using Cisco Firepower Threat Defense (FTD) with URL filtering to block access to social media sites during work hours. After implementation, users can still access Facebook and Twitter. The access control policy is configured correctly with a URL category condition. What should the administrator verify first?

⚠ Common exam trap

Cisco often tests the misconception that SSL decryption is required for URL filtering on encrypted traffic, but the correct first step is to verify DNS snooping, which provides a lightweight alternative for domain-based filtering without decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Confirm that the FTD is configured with a DNS policy to perform DNS snooping for URL filtering.

Cisco FTD uses DNS snooping to map domain names to IP addresses for URL filtering when SSL decryption is not enabled. Without DNS snooping, the FTD cannot reliably associate traffic with the requested URL category if the traffic is encrypted, leading to bypasses like users accessing Facebook and Twitter despite a blocking rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ensure that SSL decryption is enabled for the relevant traffic.

    Why it's wrong here

    URL filtering can work without SSL decryption using DNS snooping.

  • Confirm that the FTD is configured with a DNS policy to perform DNS snooping for URL filtering.

    Why this is correct

    Without DNS snooping, the FTD cannot categorize URLs for HTTPS traffic and relies on IP reputation, which may not be effective.

  • Check that the URL filtering rule is above any other permit rules.

    Why it's wrong here

    Rule order is important but if the rule is present and matching, it should block; the issue is more fundamental.

  • Verify that the FTD has an updated URL filtering database.

    Why it's wrong here

    While an updated database is important, the most immediate check is DNS snooping configuration.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.