Capture Dropped Packets on Cisco Secure Firewall Threat Defense

Troubleshoot Firewall Threat Defense using tools:
Answer Correct answer: D — use the capture command with type asp-drop to identify packets dropped by the firewall engine.

An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Threat Defense and resolve the issue?

  1. capture CAP int INSIDE match ip any host WEBSERVERIP
  2. capture CAP int OUTSIDE match ip any host WEBSERVERIP
  3. capture CAP int INSIDE match tcp any 80 host WEBSERVERIP 80
  4. capture CAP type asp-drop all headers-only Correct Answer

Community Votes

D
67%
A
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the specific command used to capture packets dropped by the firewall engine; the common trap is choosing an interface capture which only shows ingress/egress traffic, not explicitly dropped packets.

This guide explains how to capture dropped packets on a Cisco Secure Firewall Threat Defense instance. It establishes that using the asp-drop capture type is the correct method to identify packets dropped by the firewall engine.

Choosing option A because an interface capture on the inside interface will show the packet arriving, but it does not specifically isolate or identify packets that were dropped by the firewall.

Community Discussion (6 comments)

tinyJoe 👍 2 Selected: A
Very good question. It is a difficult choice, but I will choose A. As for D, asp-drop, my understanding is that ASP: Accelerated Security Path is a feature that “skips some checks on already established connections”. https://community.cisco.com/t5/network-security/what-is-asp/td-p/4043042#:~:text=If%20the%20connection%20is%20already%20established In this question, I am guessing that there is no connection to the external web server at all. If the connection is not yet established, then the asp-drop option should not be enabled. (PS: There is a discussion of this very question on Cisco Community, but even the VIP respondents are divided between A and D. LOL) https://community.cisco.com/t5/network-security/how-to-capture-dropped-packet-in-ftd-firewalll/td-p/5070863 I chose A, probably because the person with the A opinion seems more trustworthy)
Alex_morgan 👍 3 Selected: D
The asp-drop type of capture is used to identify and capture packets that are dropped by the Cisco Secure Firewall Threat Defense (FTD) appliance due to the Accelerated Security Path (ASP) process. This type of capture helps troubleshoot issues where traffic is being dropped by the firewall, which is the case in this scenario. The other options (A, B, and C) are for general packet captures, but they don't specifically capture dropped packets, which is the key part of this issue.
Amedeou 👍 3 Selected: D
To capture packets that are dropped by Cisco Secure Firewall Threat Defense (FTD) and troubleshoot the issue of traffic from the inside network to a webserver not getting through, the administrator should use the command to capture packets dropped by the accelerated security path (ASP) engine. The correct command is: capture CAP type asp-drop all headers-only
eafea4f 👍 1 Selected: A
The question doesn't specify the packets dropped.
MB2222 👍 1
(A) and (C) could be valid answers. However, (C) restricts the troubleshooting massively by saying that the client tcp source port must be 80. In regular connection requests, those source ports are randomized... So, answer (A) should be the correct one.
gwb 👍 2
My choice is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D uses the type asp-drop capture, which is specifically designed to intercept and log packets that are dropped by the Accelerated Security Path (ASP) engine within the Cisco Secure Firewall Threat Defense. When troubleshooting why traffic is not getting through, identifying the exact packets being dropped by the firewall's inspection or access policies is crucial. The asp-drop all argument captures all types of ASP drops, providing visibility into why the webserver traffic is being blocked.

Why the Other Options Are Wrong

Options A, B, and C use standard interface captures (int INSIDE or int OUTSIDE). While an ingress interface capture might show the packet arriving at the firewall, it does not filter for or indicate that the packet was subsequently dropped by the firewall's policies. Option C also incorrectly specifies the source port as 80 (tcp any 80), which is incorrect for client traffic originating from a random ephemeral port. Option B captures traffic on the outside interface, which dropped packets will never reach.

Community Comment Notes

Some learners argued for interface captures, with one noting that option C "restricts the troubleshooting massively by saying that the client tcp source port must be 80." Another commenter misunderstood the ASP engine, claiming "ASP: Accelerated Security Path is a feature that “skips some checks on already established connections”", which is incorrect; the ASP engine handles all packet processing and is where drops occur. The consensus correctly identifies that asp-drop is the required capture type for dropped packets.

Official Reference

Exam Strategy

When a question explicitly asks to capture packets "dropped" by a Cisco firewall, look for the type asp-drop keyword in the capture command options. Standard interface captures only show traffic entering or leaving, not the firewall's drop decisions.

Related Analysis

← Back to 300-710 Study Guide