nerdexam
Cisco

300-710 · Question #192

An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However if the time is exceeded the configuration must allow packets to bypass de

The correct answer is D. Automatic Application Bypass. To limit packet processing time and bypass detection if the limit is exceeded, Automatic Application Bypass (AAB) must be configured on Cisco FMC.

Configuration

Question

An engineer is configuring Cisco FMC and wants to limit the time allowed for processing packets through the interface. However if the time is exceeded the configuration must allow packets to bypass detection. What must be configured on the Cisco FMC to accomplish this task?

Options

  • AFast-Path Rules Bypass
  • BCisco ISE Security Group Tag
  • CInspect Local Traffic Bypass
  • DAutomatic Application Bypass

How the community answered

(60 responses)
  • B
    3% (2)
  • C
    2% (1)
  • D
    95% (57)

Why each option

To limit packet processing time and bypass detection if the limit is exceeded, Automatic Application Bypass (AAB) must be configured on Cisco FMC.

AFast-Path Rules Bypass

Fast-Path Rules Bypass is not a standard Cisco FTD feature configured for this specific purpose of bypassing inspection based on processing time.

BCisco ISE Security Group Tag

Cisco ISE Security Group Tags (SGTs) are used for identity-based access control and network segmentation, not for managing packet processing time.

CInspect Local Traffic Bypass

Inspect Local Traffic Bypass typically refers to bypassing inspection for traffic destined for or originating from the FTD device itself, not for general traffic inspection based on processing load.

DAutomatic Application BypassCorrect

Automatic Application Bypass (AAB) in Cisco Firepower Threat Defense (FTD) allows the system to monitor the processing time for specific applications. If the configured processing threshold is exceeded, AAB can dynamically bypass further inspection for subsequent packets of that application, preventing performance degradation and ensuring traffic flow.

Concept tested: Cisco FTD Automatic Application Bypass (AAB)

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/applications.html#ID-2187-0000010f

Topics

#Cisco FMC#Automatic Application Bypass#Firepower Threat Defense#Performance Tuning

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice