300-710 · Question #232
An engineer is deploying AMP for the first time and cannot afford any interrupted to network traffic. Which policy types does NOT disrupted the network?
The correct answer is C. Audit. To avoid network disruption when deploying AMP for the first time, an engineer should use the Audit policy type. This mode allows for passive monitoring and logging of events without actively enforcing actions or interfering with traffic flow.
Question
An engineer is deploying AMP for the first time and cannot afford any interrupted to network traffic. Which policy types does NOT disrupted the network?
Options
- AProtect
- BServer
- CAudit
- Dtnage
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C86% (24)
- D4% (1)
Why each option
To avoid network disruption when deploying AMP for the first time, an engineer should use the Audit policy type. This mode allows for passive monitoring and logging of events without actively enforcing actions or interfering with traffic flow.
The Protect policy type is an active enforcement mode that would disrupt network traffic by blocking or otherwise interfering with detected threats.
Server is not a standard AMP policy type for deployment mode. If interpreted as a policy applied to servers, it would typically involve active protection, potentially disrupting traffic.
The Audit policy type in Cisco AMP is designed for monitoring and logging events without taking any enforcement actions, ensuring that network traffic remains uninterrupted while the system gathers intelligence on potential threats.
Tnage is not a recognized Cisco AMP policy type.
Concept tested: Cisco AMP deployment modes
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/amp-for-networks-and-file-policy.html
Topics
Community Discussion
No community discussion yet for this question.