nerdexam
Cisco

300-710 · Question #159

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious…

The correct answer is B. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in. To configure Cisco FTD to detect potential intrusions without blocking suspicious traffic, an engineer must configure the intrusion policy rules to operate in detection-only mode, commonly referred to as IDS mode, under the Cisco FMC Intrusion tab. This ensures alerts are…

Configuration

Question

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic Which action accomplishes this task?

Options

  • AConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
  • BConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
  • CConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
  • DConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    81% (21)
  • C
    8% (2)
  • D
    8% (2)

Why each option

To configure Cisco FTD to detect potential intrusions without blocking suspicious traffic, an engineer must configure the intrusion policy rules to operate in detection-only mode, commonly referred to as IDS mode, under the Cisco FMC Intrusion tab. This ensures alerts are generated for threats without enforcing blocking actions.

AConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in

Configuring IPS mode (Intrusion Prevention System) implies that the system will actively block or drop suspicious traffic, which directly contradicts the requirement to 'not block the suspicious traffic.'

BConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab inCorrect

In Cisco FMC, within the Intrusion Policy, individual rules or the overall policy can be configured to operate in a detection-only capacity, often referred to as IDS mode. This means the system will identify and log potential intrusions and generate alerts, but it will not actively block or drop the suspicious traffic, fulfilling the requirement.

CConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in

This choice is identical to B and, if taken as a distinct option, does not provide a different technical reason.

DConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in

This choice is identical to B and, if taken as a distinct option, does not provide a different technical reason.

Concept tested: Cisco FTD Intrusion Policy - IDS vs IPS mode

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policies_and_rules.html

Topics

#Cisco FTD#Cisco FMC#Intrusion Policies#IDS vs IPS

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice