ECMS Practice Question - Jul 30rd

Solved
SandroZ
Meraki Employee
Meraki Employee

ECMS Practice Question - Jul 30rd

This week question is not a usual pick 1 or pick 2 but rather a 'select all that apply', I can't hide my expectations for spoiler free comments 😎 but as always you can just post what you think is the correct answer.

 

See you in a week with the correct answer(s)!

 

ECMS practice question

 

Where on Dashboard would you go to configure layer 7 firewall rules to deny traffic for specific applications? (Select all that apply)

 

  1. Security & SD-WAN > Configure > Firewall
  2. Security & SD-WAN > Configure > Site-to-site VPN
  3. Systems Manager > Configure > Policies
  4. Wireless > Configure > Firewall & traffic shaping
  5. Network-wide > Configure > Group policy

 

Here you can find previous questions

~~If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.~~

The Meraki ECMS exam is now live! Test your knowledge of Meraki and become an official Cisco Meraki Solutions Specialist. More info on the ECMS exam found here.

For information regarding all of Meraki's training offerings, be sure to check out the Meraki Learning Hub.
1 Accepted Solution
SandroZ
Meraki Employee
Meraki Employee

Better late than ever
A -D-E
were the correct answers!


Thanks everyone for participating!

 

Honorable mention to who spotted the limit case on E, available only if the network included devices capable of enforcing those L7 deny rules.

~~If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.~~

The Meraki ECMS exam is now live! Test your knowledge of Meraki and become an official Cisco Meraki Solutions Specialist. More info on the ECMS exam found here.

For information regarding all of Meraki's training offerings, be sure to check out the Meraki Learning Hub.

View solution in original post

6 Replies 6
RomanMD
Building a reputation

There are so many options, that sometimes it just makes things more difficult than simpler 😄

Spoiler
whAt if i've pickeD three of thEm?
Bruce
Kind of a big deal

I wouldn’t say it was dead easy, but a nice challenge.

PhilipDAth
Kind of a big deal
Kind of a big deal

My thoughts.

 

Spoiler
  1. Security & SD-WAN > Configure > Firewall.  Yes.
  2. Security & SD-WAN > Configure > Site-to-site VPN.  My first response is no.  I've never tried the SD-WAN Plus licence and I know it has additional application recognition options.
  3. Systems Manager > Configure > Policies.  My first response is no.  I can think of application control but that is not firewalling.
  4. Wireless > Configure > Firewall & traffic shaping.  Yes.
  5. Network-wide > Configure > Group policy.  Tricky one!  If you have an MX or MR in the network then the answer is yes, otherwise the answer is no.  For example, if you only have MS in your network then you won't see layer 7 options in group policy.
MEmami
Here to help

I would say A & D are correct answers.

SandroZ
Meraki Employee
Meraki Employee

Better late than ever
A -D-E
were the correct answers!


Thanks everyone for participating!

 

Honorable mention to who spotted the limit case on E, available only if the network included devices capable of enforcing those L7 deny rules.

~~If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.~~

The Meraki ECMS exam is now live! Test your knowledge of Meraki and become an official Cisco Meraki Solutions Specialist. More info on the ECMS exam found here.

For information regarding all of Meraki's training offerings, be sure to check out the Meraki Learning Hub.
monicajiao
Meraki Employee
Meraki Employee

may I know why this practice did not update anymore?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.