100-150 exam dumps

100-150 practice question 266 of 295

Cisco Certified Support Technician (CCST) Networking. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-150 Question 266

Select 2

A network administrator has configured a firewall to block all incoming traffic on TCP port 22 and UDP port 53. However, users report they are unable to perform DNS queries and cannot establish SSH sessions to remote servers. What could be the issue, and how should the firewall rules be adjusted to resolve this?

  1. A

    The rule blocking TCP port 22 should be removed to allow SSH connections.

  2. B

    A rule allowing UDP port 53 should be added to permit DNS queries.

  3. C

    The rule blocking UDP port 53 should be removed to permit DNS queries.

  4. D

    The rule blocking TCP port 22 should remain unchanged to ensure security.

  5. E

    A rule allowing TCP port 22 should be added to permit SSH connections.

Show answer and explanation

Correct answers: B, E

Explanation

To resolve the issue, the firewall rules should be adjusted to permit necessary traffic while maintaining security. SSH connections require TCP port 22, so an allow rule must be added for this port. Similarly, DNS queries use UDP port 53, so an allow rule should be added for this protocol and port to restore functionality. Simply removing blocks without adding explicit allow rules can create security vulnerabilities.

  • A. Incorrect.

    This option is incorrect because removing the block alone does not follow best practices. Instead, a specific allow rule should be created for TCP port 22 to permit SSH connections.

  • B. Correct.

    This option is correct because DNS queries commonly use UDP port 53, and an allow rule should be added to permit this traffic.

  • C. Incorrect.

    This option is partially correct but not the best practice. Removing a block without explicitly adding an allow rule might create unintended security gaps.

  • D. Incorrect.

    This option is incorrect because leaving the block on TCP port 22 prevents SSH sessions, which are necessary for users to connect to remote servers.

  • E. Correct.

    This option is correct because adding a rule to allow TCP port 22 permits SSH connections while maintaining control over traffic.

Timed practice exam

Take a 100-150 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam