350-401 exam dumps

350-401 practice question 297 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 297

Single answer

A network administrator is deploying a next-generation firewall (NGFW) in a corporate environment to improve security. The administrator wants to prevent employees from accessing unauthorized applications like social media during work hours while still allowing critical business applications to function. Which feature of a NGFW should the administrator configure to achieve this?

  1. A

    Application control

  2. B

    URL filtering

  3. C

    Intrusion prevention system (IPS)

  4. D

    Stateful inspection

Show answer and explanation

Correct answer: A

Explanation

Next-generation firewalls include advanced features such as application control, which allows administrators to enforce policies based on application usage rather than just ports or IP addresses. By using application control, the administrator can effectively block access to unauthorized applications like social media while permitting critical business applications to function without interference. This provides granular control over the network traffic and aligns with the needs of the scenario.

  • A. Correct.

    Application control is a key feature of a next-generation firewall that allows administrators to identify, monitor, and control access to specific applications regardless of the port or protocol used. This is the correct choice for blocking unauthorized applications like social media.

  • B. Incorrect.

    URL filtering is used to block specific websites based on their URLs or categories, but it is not suitable for identifying and controlling applications that operate over various ports and protocols.

  • C. Incorrect.

    Intrusion prevention systems (IPS) are designed to detect and block malicious traffic or threats, but they are not intended for application-level access control.

  • D. Incorrect.

    Stateful inspection is a traditional firewall feature that tracks the state of network connections, but it does not provide the ability to identify or control specific applications.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam