nerdexam
Cisco

200-201 · Question #118

What do the Security Intelligence Events within the FMC allow an administrator to do?

The correct answer is A. See if a host is connecting to a known-bad domain. Security Intelligence Events within the Cisco Firepower Management Center (FMC) provide visibility into connections made by internal hosts to known malicious or suspicious IP addresses and URLs.

Submitted by emma.c· Mar 6, 2026Security Monitoring

Question

What do the Security Intelligence Events within the FMC allow an administrator to do?

Options

  • ASee if a host is connecting to a known-bad domain.
  • BCheck for host-to-server traffic within your network.
  • CView any malicious files that a host has downloaded.
  • DVerify host-to-host traffic within your network.

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Why each option

Security Intelligence Events within the Cisco Firepower Management Center (FMC) provide visibility into connections made by internal hosts to known malicious or suspicious IP addresses and URLs.

ASee if a host is connecting to a known-bad domain.Correct

Security Intelligence (SI) in Cisco Firepower Management Center (FMC) leverages dynamically updated feeds of known-bad indicators (IP addresses, URLs, domains) to identify and block connections from internal hosts to external malicious destinations, thus allowing an administrator to see if a host is connecting to a known-bad domain. These events provide crucial context for early threat detection and incident response by identifying communication with command-and-control servers or other threat infrastructure.

BCheck for host-to-server traffic within your network.

While FMC can monitor all traffic, "host-to-server traffic within your network" is a general description of network activity, not the specific value provided by Security Intelligence events, which focus on malicious connections.

CView any malicious files that a host has downloaded.

Viewing malicious files downloaded by a host is primarily the function of Advanced Malware Protection (AMP) or intrusion prevention systems (IPS) capabilities within Firepower, not directly "Security Intelligence Events" which are focused on reputation-based blocking of network connections.

DVerify host-to-host traffic within your network.

"Host-to-host traffic within your network" is a general network monitoring capability; Security Intelligence specifically highlights connections to known malicious external entities, not just any internal host-to-host traffic.

Concept tested: Cisco Firepower Security Intelligence capabilities

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/security_intelligence.html

Topics

#FMC#security intelligence#threat intelligence#domain reputation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice