Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 400-007 Exam - Topic 4 Question 70 Discussion

You were tasked to enhance the security of a network with these characteristics:* A pool of servers is accessed by numerous data centers and remote sites* The servers are accessed via a cluster of firewalls* The firewalls are configured properly and are not dropping traffic* The firewalls occasionally cause asymmetric routing of traffic within the server data center.Which technology should you recommend to enhance security by limiting traffic that could originate from a hacker compromising a workstation and redirecting flows at the servers?
C) Limit sources of traffic that exit the server-facing interface of the firewall cluster with ACLs.
A) Poison certain subnets by adding static routes to Null0 on the core switches connected to the pool of servers.
B) Deploy uRPF strict mode.
D) Deploy uRPF loose mode

Cisco 400-007 Exam - Topic 4 Question 70 Discussion

Actual exam question for Cisco's 400-007 exam
Question #: 70
Topic #: 4
[All 400-007 Questions]

You were tasked to enhance the security of a network with these characteristics:

* A pool of servers is accessed by numerous data centers and remote sites

* The servers are accessed via a cluster of firewalls

* The firewalls are configured properly and are not dropping traffic

* The firewalls occasionally cause asymmetric routing of traffic within the server data center.

Which technology should you recommend to enhance security by limiting traffic that could originate from a hacker compromising a workstation and redirecting flows at the servers?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Elenore
4 months ago
B is the best option. It ensures only legitimate sources are allowed.
upvoted 0 times
...
Ronald
5 months ago
C is my pick too. It directly controls traffic flow.
upvoted 0 times
...
Remedios
5 months ago
D feels too relaxed. Loose mode might let too much through.
upvoted 0 times
...
Marget
5 months ago
A is interesting, but I'm not sure about poisoning subnets.
upvoted 0 times
...
Luisa
5 months ago
I agree, but C could also work well. ACLs can really limit unwanted traffic.
upvoted 0 times
...
Bobbye
5 months ago
I'm leaning towards B. uRPF strict mode seems solid for security.
upvoted 0 times
...
Nicolette
5 months ago
A) Poisoning subnets? That sounds risky!
upvoted 0 times
...
Iluminada
6 months ago
Totally agree with B! It really tightens security.
upvoted 0 times
...
Francene
6 months ago
Wait, isn’t uRPF strict mode too restrictive?
upvoted 0 times
...
Huey
6 months ago
C) Limit sources with ACLs is a good idea too!
upvoted 0 times
...
Willard
7 months ago
Poison subnets? What is this, a video game? C) is the clear winner.
upvoted 0 times
...
Marvel
7 months ago
D) uRPF loose mode? Really? That's like putting a bandaid on a bullet wound.
upvoted 0 times
...
Geoffrey
7 months ago
Hmm, I'm torn between B and C. Gotta love those asymmetric routing challenges!
upvoted 0 times
...
Carma
7 months ago
B) uRPF strict mode would be my pick to enhance security and prevent spoofing.
upvoted 0 times
...
Olive
7 months ago
C) Limiting sources of traffic with ACLs sounds like the way to go here.
upvoted 0 times
...
Oretha
7 months ago
Poisoning subnets sounds risky, but I recall it being a method to manage routing issues. I wonder if it would really enhance security in this scenario.
upvoted 0 times
...
Aliza
8 months ago
I'm a bit confused about the difference between uRPF strict and loose modes. I feel like I need to review that section again before making a decision.
upvoted 0 times
...
Darrin
8 months ago
I think limiting sources with ACLs could be effective, especially since it directly controls what can exit the firewall. I practiced a similar question on that.
upvoted 0 times
...
Jennifer
8 months ago
I remember studying about uRPF, but I'm not entirely sure if strict mode is the right choice here. It seems like it could help with asymmetric routing, though.
upvoted 0 times
...
Broderick
8 months ago
I'm feeling pretty confident about this one. Limiting the sources with ACLs is definitely the way to go to lock down that server pool and prevent potential hacker traffic.
upvoted 0 times
...
Wilbert
8 months ago
Okay, I think I've got it. The key is to limit the traffic sources on the firewall cluster to prevent any redirected flows from reaching the servers. ACLs seem like the way to go here to enhance the security.
upvoted 0 times
...
Shaun
9 months ago
I’d go with B) Deploy uRPF strict mode. Seems solid.
upvoted 0 times
...
Roselle
9 months ago
Haha, Null0 routing, now that's a blast from the past! Gotta go with C) though.
upvoted 0 times
...
Ashlee
9 months ago
Poison the subnets? I don't know, that sounds a bit risky. I'd be worried about accidentally blocking legitimate traffic. The ACL approach seems safer and more targeted.
upvoted 0 times
...
Cory
9 months ago
Hmm, I'm a bit confused. Is uRPF strict mode a better option to consider here? I'm not sure how that would work to limit the traffic compared to ACLs.
upvoted 0 times
...
Hester
10 months ago
I think I know the answer to this one. Limiting the sources of traffic with ACLs on the firewall cluster seems like the best way to enhance security and prevent potential hacker traffic from reaching the servers.
upvoted 0 times
Berry
4 months ago
I think it’s the best option too!
upvoted 0 times
...
Tandra
4 months ago
Plus, it’s a straightforward solution.
upvoted 0 times
...
Zona
4 months ago
ACLs can really help control traffic flow.
upvoted 0 times
...
Maybelle
8 months ago
Definitely, it adds an extra layer of security.
upvoted 0 times
...
Virgina
9 months ago
I agree, using ACLs makes sense!
upvoted 0 times
...
...

Save Cancel