300-415 Question 213
Single answerAn enterprise is using Cisco SD-WAN with an application-aware enterprise firewall to secure its network. The admin wants to create a policy that blocks specific social media applications while allowing business-critical applications to function without disruption. Which configuration step is required to achieve this?
- A
Create an application-aware policy that defines actions for specific application families such as 'Social Media' and attach it to the centralized policy.
- B
Enable DPI (Deep Packet Inspection) on all transport interfaces to automatically block social media applications at the data plane level.
- C
Configure a data policy to prioritize social media applications with lower precedence and attach it to the branch devices.
- D
Use the 'Application Visibility and Control' (AVC) feature to disable all entertainment-related applications.
Show answer and explanation
Correct answer: A
Explanation
The application-aware enterprise firewall in Cisco SD-WAN allows administrators to define granular policies for specific application families. By creating and attaching an application-aware policy to the centralized policy, you can block or allow specific applications across the SD-WAN fabric. This capability ensures that business-critical applications are prioritized while non-essential or restricted applications, like social media, are blocked as per enterprise requirements.
- A. Correct.
Correct. The application-aware enterprise firewall allows you to create policies that define actions for specific application families. By attaching this policy to the centralized policy, you can enforce application-specific rules across the SD-WAN infrastructure.
- B. Incorrect.
Incorrect. DPI is a feature that identifies applications by inspecting packet payloads, but enabling it alone does not block applications. DPI must be used in conjunction with policies, such as an application-aware policy.
- C. Incorrect.
Incorrect. A data policy is used to influence routing or prioritize traffic, but it does not directly block or allow specific applications.
- D. Incorrect.
Incorrect. The Application Visibility and Control (AVC) feature provides visibility into application usage and performance but does not directly block applications. Also, disabling all entertainment-related applications is overly broad and not specific to social media.