Courseiva

CCNA Configuration Questions

53 of 128 questions · Page 2/2 · Configuration · Answers revealed

76
MCQmedium

An administrator needs to create a Geolocation object in the FMC to block traffic originating from a specific country. Where is this object used?

A.In Access Control rules under the Networks tab as Country objects
B.In manual NAT rules under Original Source
C.In Identity policies to restrict user login locations
D.In Prefilter policies under Geo-FastPath
AnswerA

Countries/Regions are selected as network criteria within Access Control rules.

Why this answer

Geolocation objects are used directly within Access Control rules under the Source/Destination Country criteria.

77
MCQhard

An administrator is troubleshooting an Access Control Policy where multiple rules could potentially match a specific packet. In what order does the FMC evaluate rules within an Access Control Policy?

A.Top-down within the configured sections: first Prefilter, then Security Intelligence, then Mandatory Access Rules, then Default Access Rules, then Default Action.
B.From bottom to top, with more specific rules evaluated last.
C.Simultaneously across all rules using hardware ASIC parallel processing.
D.Based on rule hit count optimization, putting frequently matched rules at the top automatically.
AnswerA

The evaluation order follows the strict packet pipeline: Prefilter -> Security Intelligence -> Access Control (Mandatory/Default) -> Default Action.

Why this answer

Access Control rules are evaluated in a top-down, first-match manner within sections (Mandatory, Default, etc.).

78
Multi-Selectmedium

An administrator is configuring interface-level QoS on an FTD device. Which THREE parameters or features can be configured within an FTD QoS policy? (Choose three)

Select 3 answers
A.DSCP Marking
B.Active Directory user group mapping
C.Automatic IP address translation (NAT mapping)
D.Priority Queuing for critical traffic like VoIP
E.Rate Limiting (maximum bandwidth limits)
AnswersA, D, E

DSCP marking allows remarking IP precedence or differentiated services code points.

Why this answer

Qos policies on FTD support rate limiting, traffic shaping, priority queuing, and marking DSCP values.

79
MCQhard

When configuring an FTD in Transparent Mode, how is the 'Bridge Group' created?

A.In the Access Control Policy
B.In Device Management > Interfaces
C.In the Security Zone settings
D.In the Platform Settings
AnswerB

Bridge groups are interface constructs.

Why this answer

Bridge groups are created in the Device Management interface configuration section.

80
Multi-Selecteasy

An administrator is creating an Access Control Policy rule on the FMC. Which TWO elements are required to create a basic rule? (Choose two)

Select 2 answers
A.Rule Name
B.Source Security Zone
C.Action (e.g., Allow, Block, Monitor)
D.Destination Port Object
E.Intrusion Policy assignment
AnswersA, C

Every rule must have a unique descriptive name.

Why this answer

Every Access Control Policy rule requires at least an Action (e.g., Allow, Block) and a Name. Other fields like source/destination zones or applications can be set to 'Any'.

81
MCQhard

When deploying a configuration change from FMC to FTD, what is the 'Deployment' process actually doing?

A.Pushing policy and configuration updates
B.Running a connectivity test
C.Rebooting the FTD
D.Updating the Snort binary
AnswerA

This applies the new settings to the target device.

Why this answer

The deployment process pushes the configuration changes and policies to the FTD device.

82
MCQmedium

You are setting up an FTD interface. What is the difference between a 'Routed' and 'Transparent' interface mode?

A.Transparent mode operates at L2
B.Routed mode does not support VLANs
C.Transparent mode requires a default gateway
D.Routed mode requires NAT
AnswerA

Transparent mode acts as a bridge without being a hop.

Why this answer

Routed mode acts as a L3 gateway, while Transparent mode acts as a L2 bridge.

83
Multi-Selectmedium

An administrator is configuring an Identity Policy to enforce user-based access control. Which THREE identity sources are supported by the FMC for user awareness? (Choose three)

Select 3 answers
A.RADIUS Server (Authentication and Accounting)
B.Captive Portal for active web authentication
C.Syslog server log scraping without agent integration
D.Active Directory via AD Agent or Cisco ISE (Passive Authentication)
E.Local SNMP MIB walk queries
AnswersA, B, D

RADIUS can be utilized for user authentication and session mapping.

Why this answer

FMC supports Active Directory via user agent/ISE, RADIUS accounting/authentication, and captive portal for user identification.

84
Multi-Selectmedium

An administrator is setting up a new Cisco Firepower Threat Defense device and needs to configure platform-level parameters using FMC Platform Settings. Which TWO features can be configured via Platform Settings? (Choose two)

Select 2 answers
A.SSL Decryption Certificate assignment
B.Network Address Translation (NAT)
C.SNMP parameters
D.Access Control Policy rules
E.Syslog Server configuration
AnswersC, E

SNMP community strings and trap destinations are configured in Platform Settings.

Why this answer

Platform Settings manage device-level settings such as Syslog/logging configuration, SNMP, Time Synchronization (NTP), and Banner settings. Access Control Policies and NAT are configured elsewhere.

85
MCQmedium

Which type of object is best suited for defining a web server's public-to-private NAT mapping?

A.VLAN object
B.Network object (Host)
C.Port object
D.Network object (Group)
AnswerB

Host objects specify a single IP for precise mapping.

Why this answer

A Host object representing the specific server IP is required for precise Static NAT mapping.

86
MCQhard

An administrator is implementing an SSL Decryption Policy on a Cisco Firepower Threat Defense device managed by FMC. The policy must decrypt outbound HTTPS traffic to inspect for malware, but certain financial domains must be excluded from decryption to comply with privacy regulations. Which rule action should be configured for these specific financial domains in the SSL Decryption Policy?

A.Do Not Decrypt
B.Decrypt - Known Key
C.Block
D.Decrypt - Resign
AnswerA

Do Not Decrypt allows the SSL/TLS session to pass through the firewall without decryption or payload inspection.

Why this answer

To prevent inspection and decryption of sensitive traffic while allowing it to pass through the firewall, the Do Not Decrypt action is used in the SSL Decryption Policy.

87
Multi-Selecthard

An administrator is configuring an SSL Decryption Policy on the FMC. Which TWO conditions or actions can be configured within an SSL rule? (Choose two)

Select 2 answers
A.Matching traffic based on URL Categories (e.g., Banking, Gambling)
B.Applying the 'Decrypt - Resign' action
C.Configuring static route metrics for decrypted packets
D.Defining QoS rate limits for HTTPS sessions
E.Enforcing Snort 3 Intrusion rule signatures directly inside the SSL policy
AnswersA, B

SSL rules support matching traffic based on URL categories to bypass or inspect specific web traffic.

Why this answer

SSL rules allow matching on criteria such as Certificate status, URL categories, and zones, and applying actions like Do Not Decrypt, Decrypt - Resign, or Block.

88
MCQmedium

An Identity Policy is configured on the FMC to authenticate users connecting through the FTD. The administrator wants to use Active Directory as the identity source. Which mechanism must be configured to map user IP addresses to usernames without requiring explicit web authentication?

A.Captive Portal
B.Passive Authentication via AD Agent or ISE
C.Local User Database
D.RADIUS Server Authentication
AnswerB

Passive authentication monitors directory server logs or agents to map user IP addresses to usernames without user intervention.

Why this answer

Passive authentication utilizes the Cisco User Agent or Firepower Identity Services Engine (ISE) / AD agent to map IP addresses to usernames transparently.

89
MCQmedium

An administrator needs to configure NAT on an FTD device so that internal traffic destined for a partner network uses the original source IP, but the destination IP is translated from 192.168.10.50 to 172.16.50.10. What type of NAT rule is required?

A.Auto NAT Destination PAT
B.Manual NAT with Destination Translation
C.Identity NAT Destination Rule
D.Auto NAT Source Translation
AnswerB

Manual NAT rules support both source and destination IP address translation configurations.

Why this answer

Translating the destination IP address of an outgoing or incoming packet requires a Destination NAT configuration (Manual NAT with dynamic or static destination translation).

90
Multi-Selectmedium

An administrator is configuring Identity Policies on the FMC. Which TWO identity sources are supported for user mapping and authentication? (Choose two)

Select 2 answers
A.Syslog server parsing for DHCP leases
B.SNMP trap listener
C.Local FTD administrator database
D.Active Directory via Firepower User Agent
E.Cisco Identity Services Engine (ISE) via pxGrid
AnswersD, E

Active Directory integration via the User Agent provides passive user mapping.

Why this answer

FMC Identity Policies support Active Directory via User Agent or ISE/pxGrid integration, along with RADIUS and captive portal.

91
Multi-Selectmedium

Which TWO items can be used to filter traffic in a QoS policy?

Select 2 answers
A.Port object
B.User Identity
C.License status
D.Device name
E.Network object
AnswersA, E

Used for protocol classification.

Why this answer

QoS policies use Network and Port objects to classify traffic for bandwidth management.

92
MCQmedium

An FTD device is deployed behind a service provider router that performs NAT, meaning the external IP address assigned to the FTD's outside interface changes dynamically via DHCP. How should a Manual NAT rule be configured to handle outbound traffic referencing this dynamic outside IP?

A.Configure Auto NAT with a translated network object set to dynamic.
B.Use a static IP address object matching the expected DHCP lease.
C.Use Identity NAT with dynamic DHCP options.
D.Configure Dynamic PAT using the Outside Interface as the translated address.
AnswerD

Using the interface IP dynamically accommodates DHCP address changes on external interfaces.

Why this answer

When the outside interface IP is dynamic, Manual NAT can use the interface itself as the translated address (Interface PAT).

93
Multi-Selecthard

An administrator is troubleshooting a Prefilter Policy configured on an FMC. Which THREE actions are available when creating a rule in a Prefilter Policy? (Choose three)

Select 3 answers
A.Decrypt - Resign (intercept and re-sign SSL certificate)
B.Inspect with Snort 3 Intrusion Prevention
C.Slow Path (send traffic through normal inspection pipeline)
D.Block (drop traffic immediately)
E.Fast Path (bypass inspection and fast-forward traffic)
AnswersC, D, E

Slow Path forces traffic through standard access control and inspection.

Why this answer

Prefilter policies support Fast Path, Slow Path, and Block actions to handle traffic before access control and inspection.

94
MCQeasy

An administrator is configuring a new Access Control Policy on the Firepower Management Center and needs to add a rule that blocks peer-to-peer file sharing applications regardless of port. Which rule type should the administrator select?

A.NAT rule
B.Identity rule
C.Access control rule
D.Prefilter rule
AnswerC

Access control rules allow defining application filters to inspect and block traffic based on Layer 7 signatures.

Why this answer

Access Control Rules of type Access are used to allow, block, or inspect traffic. To block applications regardless of port, the administrator uses the Applications tab within an Access rule.

95
MCQhard

How do you ensure that a specific host object is only used in a specific interface?

A.Use a VLAN group
B.Use a Security Zone
C.Use a Port object
D.Use an Interface Object
AnswerD

This ties the object to an interface.

Why this answer

By using the 'Interface Objects' feature in FMC, you can restrict where a network object is valid.

96
Multi-Selectmedium

Which TWO settings are available when configuring the 'Logging' tab in an Access Control Rule?

Select 2 answers
A.Log to Cloud
B.Log every packet
C.Log at Middle
D.Log at End
E.Log at Beginning
AnswersD, E

Logs connection completion.

Why this answer

Logging can be configured at the beginning or end of a connection.

97
Multi-Selectmedium

Which TWO types of objects can be created in the FMC Object Manager?

Select 2 answers
A.Network
B.License
C.System Health
D.Dashboard
E.Port
AnswersA, E

Core object type.

Why this answer

Network and Port objects are standard types in FMC.

98
MCQmedium

An administrator is configuring a Prefilter policy to handle GRE-encapsulated traffic. Which Prefilter rule option allows handling or accelerating tunneled traffic?

A.Access Control rule with GRE protocol filter
B.SSL Decryption Policy Tunnel Decrypt
C.Tunnel rule type
D.NAT rule with Protocol Rewriting
AnswerC

Tunnel rules in Prefilter policies allow matching and processing tunneled traffic such as GRE and IPsec.

Why this answer

Prefilter policies contain specific settings for handling tunnels such as GRE or IPsec to either bypass, accelerate, or match them.

99
MCQeasy

Which tab in the Access Control Policy rule allows you to choose the 'Logging' action?

A.General
B.Inspection
C.Logging
D.Advanced
AnswerC

Correct, this is the logging configuration tab.

Why this answer

The Logging tab in the rule editor is dedicated to logging configuration.

100
Multi-Selectmedium

An administrator is managing object configurations on the FMC. Which TWO of the following are valid object types that can be created under Object Management? (Choose two)

Select 2 answers
A.Port
B.NAT Rule Set
C.Network
D.Platform Setting
E.Access Control Rule
AnswersA, C

Port objects are standard objects in FMC.

Why this answer

FMC Object Management supports Networks, Ports, URLs, Security Zones, Application Filters, and more.

101
MCQeasy

Which menu in the FMC allows you to view the list of managed FTD devices?

A.Policies > Devices
B.Devices > Device Management
C.Analysis > Devices
D.System > Devices
AnswerB

Correct, this is the central inventory.

Why this answer

Devices > Device Management is the primary menu for managing all FTD nodes.

102
MCQeasy

Which option in the Access Control Policy rule allows you to define a specific application, such as 'Facebook', to be blocked?

A.Applications
B.URL
C.Zones
D.Ports
AnswerA

The Applications tab lists categorized network apps.

Why this answer

The 'Applications' tab in an Access Control Rule allows selection of specific applications for blocking or monitoring.

103
MCQmedium

An administrator configures a security intelligence feed in the FMC to block known malicious IP addresses. Where are Security Intelligence feeds and lists applied in the FMC configuration?

A.Directly inside the Prefilter policy configuration
B.Under the Security Intelligence tab of the Access Control Policy
C.Within individual Access Control rules under the Source/Destination tabs
D.Under Objects > Security Intelligence > Rule Mapping
AnswerB

Security Intelligence settings are accessed via the dedicated tab within the Access Control Policy editor.

Why this answer

Security Intelligence is configured globally per Access Control Policy under the Security Intelligence tab to drop bad traffic before evaluation against regular access rules.

104
MCQhard

An administrator is troubleshooting an SSL Decryption policy where encrypted connections are failing. The FMC logs indicate that clients are rejecting the FTD's re-signed certificate because it is not trusted. What configuration step is missing?

A.Configure a Prefilter policy to bypass SSL handshakes for those clients.
B.Import the server's private key into the FTD certificate store.
C.Enable SSL Known Key decryption for external websites.
D.Deploy the FTD's Re-signing CA certificate to the trusted root certification authorities store of all internal client endpoints.
AnswerD

Clients must trust the CA certificate used by the FTD to sign intercepted TLS connections.

Why this answer

When using Decrypt - Resign, the FTD acts as a proxy and signs certificates with a Sub-CA. End-user machines must trust this Sub-CA certificate.

105
MCQmedium

In the FMC, what is the purpose of the 'Network Discovery Policy'?

A.To enable routing
B.To block unauthorized users
C.To define discovery scope
D.To monitor bandwidth
AnswerC

Limits which networks are monitored.

Why this answer

It is used to control which networks are monitored for host/user discovery to avoid performance impact.

106
Multi-Selecthard

Which THREE actions can be performed by an SSL Decryption Policy?

Select 3 answers
A.Do Not Decrypt
B.Redirect
C.Block
D.Decrypt
E.Monitor
AnswersA, D, E

Bypasses decryption for privacy.

Why this answer

SSL policy actions include Decrypt, Do Not Decrypt, and Monitor.

107
MCQhard

An administrator is configuring an Identity Policy with Active Directory integration. The requirement is to ensure that users who fail primary AD authentication are assigned to a restricted guest VLAN using ISE integration. Which component in the FMC architecture handles this user-to-group association?

A.Network Analysis Policy (NAP)
B.Prefilter Policy Rule Match
C.Realm Configuration under Integration Settings
D.Security Intelligence Feed
AnswerC

Realms define the connection to Active Directory, enabling the FMC to retrieve user and group memberships for identity enforcement.

Why this answer

The Realm configuration defines how the FTD connects to Active Directory (via LDAP/AD Agent) and associates users and groups for identity policies.

108
Multi-Selecthard

Which THREE components are necessary to implement passive identity monitoring in an FMC-managed Firepower system?

Select 3 answers
A.SSL Decryption policy
B.Prefilter policy
C.Realm configuration in FMC
D.Cisco Identity Services Engine (ISE) or Identity Agent
E.Identity Policy
AnswersC, D, E

The Realm links the FMC to the identity source.

Why this answer

Passive identity monitoring requires the identity agent, the identity policy, and the realm configuration to map users to IPs.

109
Multi-Selecthard

Which THREE criteria can be used to match traffic within an Access Control rule on the FMC? (Choose three)

Select 3 answers
A.Intrusion Policy Signatures
B.Device Platform Settings
C.URL Categories
D.Applications
E.Security Zones
AnswersC, D, E

URL categories can be matched in rules to control web browsing.

Why this answer

Access Control rules support matching based on Networks, Ports, Applications, URL categories, Users, and Zones.

110
MCQhard

You have a large number of NAT rules. How does the FTD process them?

A.Bottom-up
B.Specific to General
C.Top-down
D.Alphabetical
AnswerC

First match wins.

Why this answer

NAT rules are processed in a top-down order until the first match is found.

111
MCQeasy

An administrator wants to group multiple existing port objects (e.g., TCP 80, TCP 443, TCP 8080) into a single object for use in Access Control Policy rules. Which object container should be created?

A.Port Object
B.Port Group Object
C.Protocol Object
D.Application Filter Object
AnswerB

A port group object allows the aggregation of multiple port objects.

Why this answer

Port Group objects allow administrators to combine multiple port or port range objects into a single manageable item.

112
MCQmedium

You are defining an Access Control Policy rule to allow traffic. If you want to log the connection at the end of the flow only if it matches the rule, which Logging setting is appropriate?

A.Log at Beginning
B.Log at End
C.Disable Logging
D.Log Both
AnswerB

Log at End provides the full session context including byte counts.

Why this answer

Log at End of Connection captures information after the session terminates.

113
MCQmedium

How do you identify which Access Control Rule triggered a specific connection log?

A.Check the 'Policy Name' field
B.Check the 'Device Name'
C.Check the 'Ingress Zone'
D.Check the 'Rule Name' field in the connection event
AnswerD

This field directly identifies the matching rule.

Why this answer

The connection event log contains a field identifying the specific Rule Name that matched.

114
MCQhard

You are troubleshooting a connectivity issue. The traffic is being dropped by a Prefilter rule. What is the characteristic of traffic handled by a Prefilter policy?

A.It performs full IPS inspection
B.It operates at the L7 layer
C.It bypasses the Snort engine
D.It only applies to encrypted traffic
AnswerC

The primary purpose of Prefilter is to bypass the Snort engine for performance.

Why this answer

Prefilter policies provide a fast path to inspect traffic without the overhead of deep packet inspection.

115
MCQmedium

When editing an Access Control Rule, which action allows you to drop traffic while simultaneously sending a TCP RST to the client?

A.Block with Reset
B.Interactive Block
C.Block
D.Trust
AnswerA

Block with Reset provides an immediate connection closure signal.

Why this answer

The 'Block with Reset' action drops the connection and sends a reset packet to notify the sender.

116
MCQmedium

What is the result of assigning a 'Trust' action to a rule in an Access Control Policy?

A.Traffic is inspected by IPS
B.Traffic is blocked
C.Traffic is permitted without inspection
D.Traffic is decrypted
AnswerC

Trust is the bypass action.

Why this answer

Trust allows traffic through the firewall without any further inspection by the Snort engine.

117
MCQeasy

An administrator needs to create a custom Application filter object in the FMC to easily select cloud storage applications in Access Control rules. Where are application filters created?

A.Devices > Device Management > Apps
B.Objects > Object Management > Application Filters
C.System > Configuration > Application Database
D.Policies > Access Control > Applications
AnswerB

Custom application filters grouping multiple apps are created under Objects > Object Management > Application Filters.

Why this answer

Application filters are created under Objects > Object Management > Application Filters.

118
MCQhard

What occurs when an 'Interactive Block' action is used in an Access Control rule?

A.The user receives a notification page
B.The traffic is dropped
C.The traffic is automatically allowed
D.The rule is ignored
AnswerA

Interactive Block provides user feedback.

Why this answer

The user is shown a page explaining why the traffic was blocked and given an option to proceed.

119
MCQeasy

An administrator needs to configure Quality of Service (QoS) on a Cisco Firepower Threat Defense device via FMC to limit peer-to-peer traffic bandwidth. Where must the QoS policy be applied for it to take effect on traffic traversing the firewall?

A.Assigned to Access Control Policy rules directly
B.Assigned inside Prefilter Policies
C.Assigned globally in Platform Settings
D.Assigned to Security Zones in the Access Control Policy QoS tab
AnswerD

QoS policies are enabled by attaching them to security zones within the Access Control Policy.

Why this answer

QoS policies in Firepower Threat Defense are applied to security zones (either inbound or outbound relative to the zone interface) within the QoS tab of the Access Control Policy.

120
MCQmedium

An administrator configures QoS on an FTD interface to prioritize VoIP traffic. Which traffic matching mechanism within the QoS policy allows the FTD to identify VoIP traffic (such as SIP or RTP) based on Layer 7 application inspection?

A.Prefilter Policy Bandwidth Limits
B.Intrusion Policy Rule Actions
C.Access Control Rules with Application Filters
D.Platform Settings QoS Class Maps
AnswerC

QoS configuration on the FMC often relies on Access Control rule associations or matching traffic classes based on network/application objects.

Why this answer

QoS policies can match traffic based on Access Control lists or Application Filters to apply rate shaping or priority queuing.

121
MCQhard

An administrator is configuring SSL Decryption to inspect internal clients browsing external websites. The organization wants to ensure that traffic to financial and health-related websites is bypassed to maintain privacy and regulatory compliance. How should this be configured in the SSL Policy?

A.Use an Intrusion Policy rule to drop packets destined for financial URLs.
B.Create a rule matching the Financial/Health URL categories with the action 'Do Not Decrypt'.
C.Add financial servers to an SSL Decryption Known Key list.
D.Configure a Prefilter policy to fast-path financial URL categories.
AnswerB

URL filtering criteria in SSL policies allows bypassing decryption for specific sensitive categories.

Why this answer

URL categories can be used as criteria in SSL rules to specify a 'Do Not Decrypt' action for sensitive categories like Finance or Health.

122
MCQeasy

An administrator wants to ensure that specific internal subnets are never subjected to NAT translation when communicating with a partner VPN tunnel. Which NAT feature achieves this?

A.Auto NAT Static
B.Dynamic PAT
C.Port Address Translation
D.Identity NAT
AnswerD

Identity NAT maps an address to itself, preventing translation while still allowing the traffic to match a NAT rule.

Why this answer

Identity NAT (or Twice NAT where source IP equals translated source IP) ensures traffic passes without address modification.

123
Multi-Selecthard

Which THREE components of an Access Control rule can be used to identify traffic as 'Application' based?

Select 3 answers
A.Application Category
B.Device Type
C.Application Tag
D.Application Name
E.OS Version
AnswersA, C, D

Filters by group.

Why this answer

Applications are identified by the App-ID engine, which uses signatures, categories, and tags.

124
MCQhard

You are creating a custom URL category. How do you add specific domains to this category in FMC?

A.In the SSL Policy
B.Directly in the Access Control rule
C.In the Prefilter Policy
D.Via Objects > Object Management > URL
AnswerD

This is the correct location to create URL objects.

Why this answer

Custom URL objects are created in the Object Manager and then assigned to the category.

125
MCQeasy

An engineer wants to group several FTD interfaces into a single logical zone to simplify Access Control rule creation. Where are security zones created in the FMC?

A.System > Integration > Security Zones
B.Objects > Object Management > Security Zones
C.Policies > Access Control > Zones
D.Devices > Device Management > Interfaces > Zones
AnswerB

Security zones are centrally managed under Objects > Object Management > Security Zones.

Why this answer

Security zones are created under Objects > Object Management > Security Zones.

126
MCQhard

You are configuring a NAT rule and need to hide the internal network behind a single interface IP. Which NAT translation setting is required?

A.Static IP
B.Dynamic IP
C.Interface PAT
D.Identity NAT
AnswerC

Uses the interface IP address for translation.

Why this answer

Interface PAT (Port Address Translation) uses the IP of the egress interface for all source translations.

127
MCQmedium

What is the primary function of a 'Security Zone' in FMC?

A.To set bandwidth limits
B.To logically group interfaces
C.To enable routing
D.To define IP ranges
AnswerB

Simplifies policy management.

Why this answer

Security Zones allow applying the same policy to multiple interfaces at once.

128
Multi-Selectmedium

Which TWO components must be configured in FMC to enable User Identity mapping for Access Control Rules?

Select 2 answers
A.QoS Policy
B.Identity Policy
C.Network Discovery Policy
D.SSL Policy
E.Identity Realm
AnswersB, E

This dictates how the FTD performs authentication or mapping.

Why this answer

An identity realm (Active Directory connector) and the Identity Policy are both required to map users to their IP addresses.

← PreviousPage 2 of 2 · 128 questions total

Ready to test yourself?

Try a timed practice session using only Configuration questions.