How to Identify All UDP Ports in a Firepower Port Object?
A security engineer must add a new policy to block UDP traffic to one server. The engineer adds a new object. Which action must the engineer take next to identify all the UDP ports?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that a Firepower port object requires an explicit protocol and port range; the trap is assuming you can leave the port field blank to match any UDP port.
When creating a port object in Cisco Secure Firewall Management Center to match all UDP ports, the port range field is mandatory. This guide confirms the correct answer is B: define the transport protocol and specify the port range 1–65535.
Many candidates choose A, thinking an empty port field defaults to all ports, but the FMC port object mandates a port range (1–65535) to cover every UDP port.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Cisco Secure Firewall Management Center (FMC), when creating a port object, you must select the transport protocol (TCP or UDP) and then enter a port number or range. To match all UDP ports, the engineer must specify the range 1–65535; there is no built‑in option to leave the port field empty and have it mean "any port." The official FMC configuration guide states that for TCP and UDP port objects, the port field is mandatory, and entering 1–65535 covers the entire port space. Therefore, option B correctly describes the required action: define the transport protocol (UDP) and set the mandatory port range. This aligns with the exam's emphasis on precise object configuration in the Secure Firewall Management Center.Why the Other Options Are Wrong
Option A is incorrect because the port number field cannot be left empty when creating a UDP port object; the interface requires a specific port or range. Option C describes configuring an ICMP object with type and code, not a UDP port object. Option D refers to using the IP protocol number (e.g., 17 for UDP) under the "Other" protocol, which would not allow you to specify UDP ports—it defines a protocol, not a port range. Only option B matches the correct procedure for a port object that identifies all UDP ports.Community Comment Notes
Community comments largely support option B. As Silexis explained, the linked Cisco documentation shows "there is no 'blank object'" and covering all ports requires entering the range 1‑65535. d0980cc reasoned that even though leaving the port blank might seem logical, assigning the full range is safer and therefore chose B. However, tinyJoe noted that in a lab test he "verified in lab and confirmed UDP Port Object with empty port number can be added," which contradicts the official guidance; this likely reflects a version-specific or FDM quirk, but for the exam the documented mandatory range (B) is the expected answer.Official Reference
Exam Strategy
When a scenario asks how to match all ports for a protocol in a Firepower object, remember that port objects require an explicit protocol and port range; leaving the port blank is not a documented option. Always verify whether the question is about a port object or an IP protocol object, as option D would apply to the latter.
Frequently Asked Questions
Why can't I leave the port field empty to match all UDP ports in FMC?
In FMC port objects, the port field is mandatory for TCP/UDP; you must enter 1–65535 to cover all ports, as confirmed by official documentation.
What is the difference between a port object and an IP protocol object for UDP?
A port object matches TCP/UDP ports, while an IP protocol object (option D) matches the IP protocol number (e.g., 17 for UDP) but cannot specify individual ports.