ECMS MX Security Appliances and Firewall 1 — Questions and Answers
Question 1: Which Meraki MX feature allows administrators to create policies that block or allow traffic based on application type?
- Layer 7 firewall (Correct answer)
- Layer 3 ACL
- Port mirroring
- VLAN tagging
Correct answer: Layer 7 firewall
The Meraki MX Layer 7 firewall enables traffic control based on application identity, not just IP and port.
Question 2: What is the primary purpose of the Meraki MX Auto VPN feature?
- It automatically encrypts all local LAN traffic
- It establishes site-to-site VPN tunnels with zero-touch configuration (Correct answer)
- It replaces IPsec with SSL VPN automatically
- It auto-generates firewall rules for VPN peers
Correct answer: It establishes site-to-site VPN tunnels with zero-touch configuration
Auto VPN uses the Meraki cloud to exchange VPN parameters and automatically establish IPsec tunnels between MX appliances.
Question 3: Which MX deployment mode places the appliance in the path of all traffic as the primary gateway?
- Passthrough mode
- VPN concentrator mode
- Routed mode (Correct answer)
- Tap mode
Correct answer: Routed mode
In routed mode, the MX acts as the default gateway and all traffic flows through it for inspection and policy enforcement.
Question 4: What does the Meraki MX Content Filtering feature use to categorize websites?
- Local DNS blacklists only
- Webroot BrightCloud URL database (Correct answer)
- Google Safe Browsing API
- Manual administrator URL lists
Correct answer: Webroot BrightCloud URL database
Meraki MX Content Filtering leverages the Webroot BrightCloud cloud-based URL categorization service for web filtering.
Question 5: When configuring Meraki MX in One-Armed Concentrator mode, where is it typically deployed?
- At the branch office as the primary gateway
- At the data center to terminate VPN tunnels without being inline (Correct answer)
- On the DMZ for public-facing services
- As a WAN edge device replacing the ISP router
Correct answer: At the data center to terminate VPN tunnels without being inline
One-Armed Concentrator mode is used at a data center or hub site to aggregate VPN tunnels without disrupting the existing routing infrastructure.
Question 6: Which Meraki MX feature provides threat protection by inspecting files passing through the appliance against known malware signatures?
- Advanced Malware Protection (AMP) (Correct answer)
- Intrusion Detection System only
- Layer 7 application blocking
- DNS sinkholing
Correct answer: Advanced Malware Protection (AMP)
Meraki Advanced Malware Protection (AMP), powered by Cisco AMP, provides file reputation scoring and retrospective alerts for malicious files.
Which Meraki MX feature allows administrators to create policies that block or allow traffic based on application type?