nerdexam
Cisco

300-710 · Question #235

What is a purpose of the network analysis policy on a Cisco Firepower NGIPS?

The correct answer is B. it governs how traffic is preprocessed before inspection. The network analysis policy on a Cisco Firepower NGIPS is crucial for preparing traffic for deeper inspection. Its purpose is to define how traffic is preprocessed and normalized before intrusion rules and other advanced analysis are applied.

Configuration

Question

What is a purpose of the network analysis policy on a Cisco Firepower NGIPS?

Options

  • Ait defines the rules for encrypting traffic
  • Bit governs how traffic is preprocessed before inspection
  • Cit examines packets for attacks by using intrusion rules
  • Dit specifies the outer-header criteria used to process traffic without using advanced inspection

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    90% (26)
  • C
    7% (2)

Why each option

The network analysis policy on a Cisco Firepower NGIPS is crucial for preparing traffic for deeper inspection. Its purpose is to define how traffic is preprocessed and normalized before intrusion rules and other advanced analysis are applied.

Ait defines the rules for encrypting traffic

Rules for encrypting traffic are typically handled by VPN policies or other cryptographic configurations, not the network analysis policy.

Bit governs how traffic is preprocessed before inspectionCorrect

The network analysis policy in Cisco Firepower Next-Generation IPS (NGIPS) determines how network traffic is normalized and preprocessed. This includes tasks like TCP stream reassembly, fragmentation reassembly, and other preparations before the traffic is subjected to detailed intrusion rule inspection.

Cit examines packets for attacks by using intrusion rules

Examining packets for attacks using intrusion rules is the function of the intrusion policy, which operates after traffic has been preprocessed by the network analysis policy.

Dit specifies the outer-header criteria used to process traffic without using advanced inspection

Specifying outer-header criteria without advanced inspection typically relates to access control lists (ACLs) or initial policy matching, not the network analysis policy's preprocessing role.

Concept tested: Cisco Firepower network analysis policy

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policy_and_rules.html

Topics

#Cisco Firepower#NGIPS#Network Analysis Policy#Traffic Preprocessing

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice