nerdexam
Cisco

300-710 · Question #158

An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be co

The correct answer is B. prefilter. To optimize network performance and reduce the load on a Cisco FTD by bypassing deep inspection for specific traffic, a prefilter policy must be configured. This policy can quickly permit or block traffic, preventing it from undergoing further resource-intensive inspection.

Configuration

Question

An administrator is optimizing the Cisco FTD rules to improve network performance, and wants to bypass inspection for certain traffic types to reduce the load on the Cisco FTD. Which policy must be configured to accomplish this goal?

Options

  • Aintrusion
  • Bprefilter
  • CURL filtering
  • Didentity

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    92% (35)
  • D
    5% (2)

Why each option

To optimize network performance and reduce the load on a Cisco FTD by bypassing deep inspection for specific traffic, a prefilter policy must be configured. This policy can quickly permit or block traffic, preventing it from undergoing further resource-intensive inspection.

Aintrusion

Intrusion policies define how traffic is inspected for threats and what actions to take, but they do not provide a mechanism to bypass inspection for performance optimization.

BprefilterCorrect

Prefilter policies in Cisco FTD are processed at a very early stage, even before access control rules and deeper inspection. They are designed to quickly permit or block certain traffic, effectively allowing administrators to bypass resource-intensive inspection for known safe or high-volume traffic to reduce the load on the FTD device and improve performance.

CURL filtering

URL filtering is a specific inspection capability for web traffic based on destination URLs, not a general mechanism to bypass all types of inspection for performance.

Didentity

Identity policies are used for user and group identification, which can then be used in other policy types, but they do not directly offer a way to bypass inspection for performance.

Concept tested: Cisco FTD Prefilter policies for performance optimization

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/prefilter_policies.html

Topics

#Cisco FTD#Prefilter Policy#Performance Optimization#Traffic Inspection Bypass

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice