Which description of the issue is true?

Refer to the exhibit. The security engineer is troubleshooting internal access to the public DNS server at 209.165.200.226.

Which description of the issue is true?
A. The routes of the Cisco ASA are incorrectly identifying traffic from 10.10.10.1 on the outside interface of the firewall.
B. To accurately test DNS, the packet tracer should be run using packet type UDP and destination port 53.
C. To allow DNS, a rule specifically allowing the DNS access must be added in the rule base.
D. The engineer must verify the NAT rules of the firewall to ensure that correct NATing is taking place.

cisco-exams

5 thoughts on “Which description of the issue is true?

  1. Packet type “IP” hits both tcp/udp…so I think the only configuration error in the packet tracer’s screnshoot is the Access-List.
    Answer: C

    1. +You mean “B” ?:

      B. To accurately test DNS, the packet tracer should be run using packet type UDP and destination port 53.

      +The screenshot has to be wrong or the answer is wrong you cannot do a packet tracer with protocol IP 53 ….

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.