Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-710 Exam - Topic 4 Question 100 Discussion

An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Throat Defense and resold the issue?
B) capture CAP type asp-drop all headers-only
A) capture CAP int OUTSIDE match ip any host WEBSERVERIP
C) capture CAP int INSIDE match ip any host WEBSERVERIP
D) capture CAP int INSIDE match tcp any 80 host WEBSERVERlP 80

Cisco 300-710 Exam - Topic 4 Question 100 Discussion

Actual exam question for Cisco's 300-710 exam
Question #: 100
Topic #: 4
[All 300-710 Questions]

An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Throat Defense and resold the issue?

Show Suggested Answer Hide Answer
Suggested Answer: B

To capture packets that are dropped by Cisco Secure Firewall Threat Defense (FTD) and troubleshoot the issue of traffic from the inside network to a webserver not getting through, the administrator should use the command to capture packets dropped by the accelerated security path (ASP) engine. The correct command is:

capture CAP type asp-drop all headers-only

This command captures all packets dropped by the ASP engine, which includes packets that are being blocked by access control policies, NAT issues, or other security checks.

Steps:

Access the FTD CLI.

Run the command capture CAP type asp-drop all headers-only to capture dropped packets.

Analyze the captured data to identify the cause of the drops.

This command provides detailed information on why packets are being dropped, helping the administrator resolve the issue.


Contribute your Thoughts:

0/2000 characters
Scarlet
9 months ago
I thought it was A at first, but B makes sense for this scenario.
upvoted 0 times
...
Ozell
9 months ago
C seems more logical since we're capturing from the inside.
upvoted 0 times
...
Kati
10 months ago
Wait, are we sure about B? What if the traffic isn't TCP?
upvoted 0 times
...
Eileen
10 months ago
Definitely agree with B, it's straightforward for ASP drops.
upvoted 0 times
...
Johnson
10 months ago
I think option B is the right command for dropped packets.
upvoted 0 times
...
Felicia
10 months ago
I’m leaning towards option D since it specifies TCP traffic on port 80, which is what the webserver would be using, but I’m not entirely sure if that’s the right approach.
upvoted 0 times
...
Luann
11 months ago
I feel like we did a similar question where we had to match traffic to a specific host. I think it was about using the INSIDE interface, maybe option C?
upvoted 0 times
...
Dewitt
11 months ago
I think option B sounds familiar from our labs, capturing ASP drops could help identify the issue, but I’m not completely confident.
upvoted 0 times
...
Andree
11 months ago
I remember we practiced packet captures, but I’m not sure if it’s the OUTSIDE or INSIDE interface that I should be using for this scenario.
upvoted 0 times
...
Chauncey
11 months ago
Hmm, I'm not sure if any of these options are exactly right. Maybe I should try to think through the problem step-by-step and see if I can come up with a better solution.
upvoted 0 times
...
Francesco
11 months ago
I'm pretty confident that option A is the correct answer. Capturing the traffic on the OUTSIDE interface and matching it to the webserver IP address seems like the best way to identify the dropped packets.
upvoted 0 times
...
Wei
11 months ago
Wait, I'm a bit confused. Shouldn't we be capturing the traffic on the OUTSIDE interface since that's where the webserver is located? I'm not sure if option C is the right choice.
upvoted 0 times
...
Soledad
11 months ago
Okay, I think I've got this. The key is to capture the packets that are being dropped by the Secure Firewall Threat Defense, so I'm going to go with option C.
upvoted 0 times
...
Andrew
11 months ago
Hmm, this looks like a tricky one. I'll need to carefully read through the options and think about the specific requirements of the question.
upvoted 0 times
...
Julene
2 years ago
Option B seems a bit too broad to me. I'd rather target the specific traffic to the webserver.
upvoted 0 times
Melvin
2 years ago
User 3: Yeah, option B does seem too broad. Option A or C would be better for capturing specific traffic to the webserver.
upvoted 0 times
...
Rolande
2 years ago
User 2: I agree, option A seems like the most targeted approach to troubleshoot the issue.
upvoted 0 times
...
Alyce
2 years ago
User 1: I think option A is the best choice. It captures packets to the webserver from the outside network.
upvoted 0 times
...
...
Jade
2 years ago
Haha, 'Secure Firewall Throat Defense' - I wonder if that's a new feature to help you cough up the dropped packets!
upvoted 0 times
...
Refugia
2 years ago
I was thinking the same thing as Paris. D is the clear winner in my opinion.
upvoted 0 times
...
Paris
2 years ago
Hmm, I think option D is the way to go here. Capturing the TCP traffic between the inside and the webserver on port 80 should give us the information we need.
upvoted 0 times
Matt
2 years ago
User 4: Hopefully this will give us the information we need to fix the network problem.
upvoted 0 times
...
Sharan
2 years ago
User 3: Let's go ahead and use that command to capture the packets.
upvoted 0 times
...
Altha
2 years ago
User 2: Agreed, capturing TCP traffic on port 80 should help us troubleshoot.
upvoted 0 times
...
Rosendo
2 years ago
User 1: I think option D is the best choice here.
upvoted 0 times
...
...
Kent
2 years ago
I disagree, I believe the correct answer is C) capture CAP int INSIDE match ip any host WEBSERVERIP.
upvoted 0 times
...
Sherita
2 years ago
I think the answer is A) capture CAP int OUTSIDE match ip any host WEBSERVERIP.
upvoted 0 times
...

Save Cancel