nerdexam
Cisco

300-710 · Question #209

A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC. Which action must be selected to enable fewer rules detect only critical conditions and avoid fals

The correct answer is A. Connectivity Over Security. To enable intrusion protection with Cisco FTDs managed by Cisco FMC that uses fewer rules to detect only critical conditions and minimize false positives, the "Connectivity Over Security" action must be selected. This setting prioritizes network uptime and minimal disruption over

Configuration

Question

A company is in the process of deploying intrusion protection with Cisco FTDs managed by a Cisco FMC. Which action must be selected to enable fewer rules detect only critical conditions and avoid false positives?

Options

  • AConnectivity Over Security
  • BBalanced Security and Connectivity
  • CMaximum Detection
  • DNo Rules Active

How the community answered

(23 responses)
  • A
    96% (22)
  • D
    4% (1)

Why each option

To enable intrusion protection with Cisco FTDs managed by Cisco FMC that uses fewer rules to detect only critical conditions and minimize false positives, the "Connectivity Over Security" action must be selected. This setting prioritizes network uptime and minimal disruption over exhaustive threat detection.

AConnectivity Over SecurityCorrect

The "Connectivity Over Security" setting in Cisco FMC's intrusion policy is designed to enable a minimal set of intrusion rules, focusing primarily on critical vulnerabilities and severe threats. This approach significantly reduces the number of active rules, thereby minimizing the likelihood of false positives and optimizing performance, aligning with the goal of detecting only critical conditions while prioritizing connectivity.

BBalanced Security and Connectivity

"Balanced Security and Connectivity" aims for a middle ground, enabling a moderate number of rules that balance threat detection with network performance, which might still generate more false positives than desired for critical conditions only.

CMaximum Detection

"Maximum Detection" is designed to enable the most comprehensive set of intrusion rules to detect a wide range of threats, which would inherently lead to a higher potential for false positives and is opposite to the stated goal.

DNo Rules Active

"No Rules Active" would disable all intrusion rules, leaving the network unprotected from intrusion threats, which contradicts the goal of deploying "intrusion protection."

Concept tested: Cisco FTD intrusion policy base policies

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-640/intrusion_policies_and_rules.html#concept_3s4_z5z_v1b

Topics

#Cisco FTD#Cisco FMC#IPS Policy#False Positive Reduction

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice