300-710 · Question #159
A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious…
The correct answer is B. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in. To configure Cisco FTD to detect potential intrusions without blocking suspicious traffic, an engineer must configure the intrusion policy rules to operate in detection-only mode, commonly referred to as IDS mode, under the Cisco FMC Intrusion tab. This ensures alerts are…
Question
A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic Which action accomplishes this task?
Options
- AConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
- BConfigure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
- CConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
- DConfigure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in
How the community answered
(26 responses)- A4% (1)
- B81% (21)
- C8% (2)
- D8% (2)
Why each option
To configure Cisco FTD to detect potential intrusions without blocking suspicious traffic, an engineer must configure the intrusion policy rules to operate in detection-only mode, commonly referred to as IDS mode, under the Cisco FMC Intrusion tab. This ensures alerts are generated for threats without enforcing blocking actions.
Configuring IPS mode (Intrusion Prevention System) implies that the system will actively block or drop suspicious traffic, which directly contradicts the requirement to 'not block the suspicious traffic.'
In Cisco FMC, within the Intrusion Policy, individual rules or the overall policy can be configured to operate in a detection-only capacity, often referred to as IDS mode. This means the system will identify and log potential intrusions and generate alerts, but it will not actively block or drop the suspicious traffic, fulfilling the requirement.
This choice is identical to B and, if taken as a distinct option, does not provide a different technical reason.
This choice is identical to B and, if taken as a distinct option, does not provide a different technical reason.
Concept tested: Cisco FTD Intrusion Policy - IDS vs IPS mode
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policies_and_rules.html
Topics
Community Discussion
No community discussion yet for this question.