200-201 exam dumps

200-201 practice question 233 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 233

Single answer

A network administrator notices that employees are using a cloud-based file-sharing application that violates the organization's security policy. To enforce compliance, the administrator wants to block the application while allowing web browsing traffic to continue. Which of the following tools or techniques would be MOST effective in achieving this?

  1. A

    Implementing IP-based Access Control Lists (ACLs)

  2. B

    Using a Next-Generation Firewall (NGFW) with application control

  3. C

    Blocking the application domain using DNS filtering

  4. D

    Configuring port-based restrictions on the firewall

Show answer and explanation

Correct answer: B

Explanation

Next-Generation Firewalls (NGFWs) with application control are specifically designed to inspect traffic at the application layer, allowing administrators to block or allow specific applications while maintaining access to others. This level of granularity is essential for enforcing security policies in modern networks where applications often share common protocols and ports.

  • A. Incorrect.

    IP-based ACLs operate at the network layer and cannot differentiate between specific applications using the same IP address or port. This is insufficient for blocking a specific application while allowing others.

  • B. Correct.

    Next-Generation Firewalls (NGFWs) with application control can inspect application-layer traffic, identify specific applications, and enforce policies to block or allow them regardless of the port or protocol used. This is the most effective option.

  • C. Incorrect.

    DNS filtering blocks access to specific domains but may not be effective for applications that use multiple domains or dynamic IPs. It also does not provide granular application control.

  • D. Incorrect.

    Port-based restrictions block traffic based on port numbers, which is not effective for modern applications that use dynamic ports or common ports like 443 (HTTPS).

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam