300-710 · Question #235
What is a purpose of the network analysis policy on a Cisco Firepower NGIPS?
The correct answer is B. it governs how traffic is preprocessed before inspection. The network analysis policy on a Cisco Firepower NGIPS is crucial for preparing traffic for deeper inspection. Its purpose is to define how traffic is preprocessed and normalized before intrusion rules and other advanced analysis are applied.
Question
What is a purpose of the network analysis policy on a Cisco Firepower NGIPS?
Options
- Ait defines the rules for encrypting traffic
- Bit governs how traffic is preprocessed before inspection
- Cit examines packets for attacks by using intrusion rules
- Dit specifies the outer-header criteria used to process traffic without using advanced inspection
How the community answered
(29 responses)- A3% (1)
- B90% (26)
- C7% (2)
Why each option
The network analysis policy on a Cisco Firepower NGIPS is crucial for preparing traffic for deeper inspection. Its purpose is to define how traffic is preprocessed and normalized before intrusion rules and other advanced analysis are applied.
Rules for encrypting traffic are typically handled by VPN policies or other cryptographic configurations, not the network analysis policy.
The network analysis policy in Cisco Firepower Next-Generation IPS (NGIPS) determines how network traffic is normalized and preprocessed. This includes tasks like TCP stream reassembly, fragmentation reassembly, and other preparations before the traffic is subjected to detailed intrusion rule inspection.
Examining packets for attacks using intrusion rules is the function of the intrusion policy, which operates after traffic has been preprocessed by the network analysis policy.
Specifying outer-header criteria without advanced inspection typically relates to access control lists (ACLs) or initial policy matching, not the network analysis policy's preprocessing role.
Concept tested: Cisco Firepower network analysis policy
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policy_and_rules.html
Topics
Community Discussion
No community discussion yet for this question.