300-415 · Question #356
Which signature sets are available in vManage under the security policy configuration for IPS?
The correct answer is A. Connectivity, Balanced, Security. In vManage's IPS security policy configuration, the three available signature sets are Connectivity, Balanced, and Security, each representing a different trade-off between inspection aggressiveness and performance.
Question
Exhibits
Options
- AConnectivity, Balanced, Security
- BMalware, Blacklist, Connectivity
- CMalware, Security, Connectivity
- DBlacklist, Balanced, Security
How the community answered
(28 responses)- A96% (27)
- B4% (1)
Why each option
In vManage's IPS security policy configuration, the three available signature sets are Connectivity, Balanced, and Security, each representing a different trade-off between inspection aggressiveness and performance.
vManage IPS offers three predefined signature sets - Connectivity (minimal inspection, prioritizes traffic flow), Balanced (moderate inspection balancing performance and security), and Security (maximum inspection for highest threat detection). These sets allow administrators to choose the appropriate trade-off between network performance and security posture without manually tuning individual signatures.
Malware and Blacklist are not signature set names used in the vManage IPS configuration; the correct sets are Connectivity, Balanced, and Security.
Malware is not one of the three IPS signature sets available in vManage; Connectivity, Balanced, and Security are the correct and only options.
Blacklist is not one of the three IPS signature sets in vManage; the correct signature sets are Connectivity, Balanced, and Security.
Concept tested: vManage IPS signature set options identification
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/intrusion-prevention.html
Topics
Community Discussion
No community discussion yet for this question.

