350-201 exam dumps

350-201 practice question 80 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 80

Single answer

Your company has recently deployed Cisco Firepower Threat Defense (FTD) appliances to improve network security. The network consists of different departments such as Finance, HR, and Research & Development (R&D). You are tasked with implementing segmentation to isolate traffic between these departments while allowing specific inter-department communication, such as HR accessing a Finance payroll application. Which approach would be the most effective way to achieve this using Cisco FTD?

  1. A

    Create separate VLANs for each department and configure Access Control Policies (ACPs) on Cisco FTD to allow or deny traffic between them as required.

  2. B

    Deploy a single VLAN across all departments and use Cisco FTD to block unauthorized traffic using URL filtering.

  3. C

    Use Cisco FTD to create a flat network and rely on endpoint security to prevent unauthorized communication.

  4. D

    Configure a single Access Control Policy (ACP) on Cisco FTD to allow all traffic between departments and monitor for malicious activity.

Show answer and explanation

Correct answer: A

Explanation

Network segmentation is a critical security practice to isolate traffic and reduce the attack surface. By creating separate VLANs for each department, you establish Layer 2 isolation. Cisco FTD's Access Control Policies (ACPs) further enhance segmentation by providing granular control over the specific types of traffic allowed between departments, ensuring both security and operational requirements are met.

  • A. Correct.

    This is correct. Creating separate VLANs for each department ensures traffic isolation at Layer 2, while Access Control Policies (ACPs) on Cisco FTD provide fine-grained control over inter-department communication.

  • B. Incorrect.

    This is incorrect. A single VLAN across all departments does not provide traffic isolation, and URL filtering is not suitable for controlling inter-department communication.

  • C. Incorrect.

    This is incorrect. A flat network does not provide segmentation, and relying solely on endpoint security leaves the network vulnerable to lateral movement of threats.

  • D. Incorrect.

    This is incorrect. Allowing all traffic by default does not implement segmentation and increases the risk of unauthorized access between departments.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam