Cisco CCNP Security Core (SCOR) 350-701Content SecurityHard
A security engineer is troubleshooting an issue where legitimate web traffic to a critical business application is being unexpectedly blocked by a Cisco Firepower Threat Defense (FTD) device. The application uses a custom, non-standard port and relies on specific HTTP headers for authentication. Which two components should the engineer primarily investigate to resolve this issue and ensure proper application access while maintaining security?
- ASecurity Intelligence and File Policy
- BIntrusion Policy and URL Filtering policy
- CNetwork Analysis Policy and SSL Policy
- DAccess Control Policy and Application Detector
Show answer & explanationAnswer & explanation
Correct answer: D. Access Control Policy and Application Detector
The Access Control Policy (ACP) defines what traffic is allowed or blocked, including ports and application-level rules. The Application Detector specifically identifies applications, even those on non-standard ports or using custom headers, allowing the ACP to correctly classify and permit the legitimate application traffic.
Why the other options are wrong
- A. Security Intelligence blocks known bad IPs/URLs, and File Policy controls file transfers; neither is the primary cause or solution for legitimate application traffic on custom ports being blocked.
- B. Intrusion Policy focuses on attack detection, and URL filtering blocks web categories, neither directly addresses blocking due to custom ports or headers for legitimate apps.
- C. Network Analysis Policy deals with protocol compliance and vulnerabilities, while SSL Policy handles decryption, which might be involved but isn't the primary component for initial blocking or application identification based on custom ports/headers.
Cisco FTD Application Identification
Cisco Firepower Threat Defense uses deep packet inspection and an Application Detector to identify applications, independent of port or protocol, for granular access control.
- Identifies applications regardless of port.
- Uses signatures, heuristics, and behavioral analysis.
- Enables granular Access Control Policy enforcement.
Memory trick: Access Control permits, Application Detector identifies.