SNCF — Securing Networks with Firepower — Question 127

An engineer is troubleshooting connectivity to the DNS servers from hosts behind a new Cisco FTD device. The hosts cannot send DNS queries to servers in the DMZ. Which action should the engineer take to troubleshoot this issue using the real DNS packets?

Answer options

Correct answer: A

Explanation

Option A is correct because using the packet capture tool allows the engineer to analyze the actual DNS packets and pinpoint where the traffic is being blocked, enabling necessary adjustments to the policies. The other options do not provide a direct method for capturing and analyzing real DNS packets, making them less effective for this specific troubleshooting scenario.