ETExamTower
Q17Remote access VPNs

An engineer is configuring a clientless SSL VPN. The finance department has a database server that only it should be able to access, but the sales department can currently reach it. Finance and sales are configured as separate group policies. What must be added to ensure that sales department users cannot access the finance department server?

← → navigate · a answer
Community votes
D
70% (7)
A
20% (2)
C
10% (1)
B
0% (0)
Discussion · 14
A 3
Selected Answer: A It is A https://www.youtube.com/watch?v=I5gbHC-stm4
3
"D". To make sure users in the sales department cannot access the finance department server in a clientless SSL VPN setup, a webtype ACL (Access Control List) has to be added to the configuration. A webtype ACL is used to define specific access controls for clientless SSL VPN users. It lets you control and restrict the resources that users can access through the SSL VPN portal. By creating a webtype ACL and applying it to the right group-policy tied to the sales department, you can explicitly block access to the finance department server. This ACL will stop users in the sales department from reaching the finance department server even though they are set up under separate group-policies. On the other hand, "tunnel group lock" is not directly related to restricting access to specific resources. It is a feature that lets you lock a user to a specific tunnel group, ensuring that the user always connects to that particular tunnel group. So, the correct way to stop users in the sales department from accessing the finance department server in a clientless SSL VPN setup is to use a webtype ACL.
3
Web ACLs let administrators control the resources users can access when they make access requests through a clientless SSL VPN.
D 3
Selected Answer: D Web ACLs let administrators control the resources users can access when they make access requests through a clientless SSL VPN.
2
A is correct. Reference https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/acl-webtype.pdf
D 2
Selected Answer: D D is correct https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/acl-webtype.html
D 2
Selected Answer: D D is the only correct answer
D 1
Selected Answer: D Excuse me. The correct answer is D Web type ACL Reference https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/acl-webtype.pdf
D 1
Selected Answer: D Agree. D is correct by using webtype ACLs.
D 1
Selected Answer: D Agree. D
1
A should be correct, we want to restrict users from accessing a certain host. But if we only use an ACL and the user can access another tunnel group, they will have access according to the other tunnel-group.
A 1
Selected Answer: A Database access does not seem to be controlled by webtype ACL's... We can't know because it does not say which protocol is used. So I'd pick answer A.
1
The correct answer is D. webtype ACL ! User Anonymous983475 says: But if we use only one ACL and the user can access another tunnel group, he will have the access according to the other tunnel group. That's not really right, because we can assign a specific group policy to the remote users that prevents access even if he uses a different tunnel group: ASA(config)# access-list WebACL_SALES_DEPARTMENT webtype permit url http://192.168.10.100 log default ASA(config)# access-list WebACL_FINANCE_DEPARTMENT webtype permit url http://192.168.20.100 log default ASA(config)# group-policy sales_department internal ASA(config)# group-policy sales_department attributes ASA(config-group-policy)# vpn-tunnel-protocol ssl-clientless ASA(config-group-policy)# webvpn ASA(config-group-webvpn)# filtervalue WebACL_SALES_DEPARTMENT ASA(config)# username RemoteUser1 password xxx ASA(config)# username RemoteUser1 attribute ASA(config-username)# vpn-group-policy sales_department
C 1
Selected Answer: C Correct answer: ✅ D. webtype ACL Explanation: For clientless SSL VPN, access control for internal web resources is enforced with WebType ACLs, not traditional IP ACLs. Because the finance and sales departments already have separate group policies, a WebType ACL has to be added to restrict the sales group from accessing the finance database server. This gives exact control over which URLs, servers, or web resources each group can reach. Why the other options are incorrect: A. tunnel group lock Locks users to a tunnel group but does not control resource access. B. smart tunnel Used for handling nonstandard applications, not for access restriction. C. port forwarding Provides access mechanisms but does not enforce authorization.