300-710 · Question #204
An organization recently implemented a transparent Cisco FTD in their network. They must ensure that the device does not respond to insecure SSL/TLS protocols. Which action accomplishes this task?
The correct answer is B. Use the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2.. To prevent a transparent Cisco FTD from responding to insecure SSL/TLS protocols, the administrator must configure the minimum SSL version to TLS 1.2 or higher within the FTD platform policy.
Question
An organization recently implemented a transparent Cisco FTD in their network. They must ensure that the device does not respond to insecure SSL/TLS protocols. Which action accomplishes this task?
Options
- AModify the device's settings using the device management feature within Cisco FMC to force only
- BUse the Cisco FTD platform policy to change the minimum SSL version on the device to TLS 1.2.
- CEnable the UCAPL/CC compliance on the device to support only the most secure protocols
- DConfigure a FlexConfig object to disable any insecure TLS protocols on the Cisco FTD device.
How the community answered
(32 responses)- A3% (1)
- B78% (25)
- C13% (4)
- D6% (2)
Why each option
To prevent a transparent Cisco FTD from responding to insecure SSL/TLS protocols, the administrator must configure the minimum SSL version to TLS 1.2 or higher within the FTD platform policy.
Modifying 'device's settings using the device management feature' is too generic; the platform policy is the specific and correct mechanism for this configuration.
The Cisco FTD platform policy within Cisco FMC allows administrators to define global device settings, including cryptographic standards and the minimum acceptable SSL/TLS version. By setting the minimum SSL version to TLS 1.2 or higher, the FTD device's own management interfaces and potentially other SSL-enabled services will reject connections or responses using older, insecure protocols.
Enabling UCAPL/CC compliance indicates adherence to standards but does not directly configure the specific SSL/TLS versions on the device; specific settings are made via policy.
While FlexConfig can apply custom CLI, the platform policy offers a native, supported, and integrated way to manage SSL/TLS versions for the FTD device.
Concept tested: Cisco FTD platform policy SSL/TLS settings
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/device_platform_settings.html
Topics
Community Discussion
No community discussion yet for this question.