Which option must be added to the configuration to make sure the users in the sales department cannot access the finance department server?

An engineer is configuring clientless SSL VPN. The finance department has a database server that only they should access, but the sales department can currently access it. The finance and the sales departments are configured as separate group-policies. Which option must be added to the configuration to make sure the users in the sales department cannot access the finance department server?
A. tunnel group lock
B. webtype ACL
C. port forwarding
D. VPN filter ACL

cisco-exams

2 thoughts on “Which option must be added to the configuration to make sure the users in the sales department cannot access the finance department server?

  1. A is the right answer because the group-lock feature on the ASA restricts a user to a specific tunnel group.

  2. Its webtype ACL. Tunnel group-lock only controls which connection profile a user can log in to. The ACL allows or denys access to resources on the network.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.