nerdexam
Cisco

300-710 · Question #281

A security engineer must configure policies for a recently deployed Cisco FTD. The security policy for the company dictates that when five or more connections from external sources are initiated…

The correct answer is C. correlation. To generate an alert when five or more connections are initiated from external sources within 2 minutes, a correlation policy must be configured in Cisco FMC.

Configuration

Question

A security engineer must configure policies for a recently deployed Cisco FTD. The security policy for the company dictates that when five or more connections from external sources are initiated within 2 minutes, there is cause for concern. Which type of policy must be configured in Cisco FMC to generate an alert when this condition is triggered?

Options

  • Aapplication detector
  • Baccess control
  • Ccorrelation
  • Dintrusion

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    80% (24)
  • D
    10% (3)

Why each option

To generate an alert when five or more connections are initiated from external sources within 2 minutes, a correlation policy must be configured in Cisco FMC.

Aapplication detector

An application detector identifies applications but does not monitor the frequency or rate of connections over time to trigger alerts based on thresholds.

Baccess control

An access control policy permits or denies traffic based on rules, but it does not inherently monitor event frequency or generate alerts based on connection thresholds over time.

CcorrelationCorrect

A correlation policy in Cisco FMC is specifically designed to analyze multiple security events over a defined time period and trigger an action, such as an alert, when specific conditions or patterns, like a high rate of connections from external sources, are met. This allows detection of complex, time-based threat indicators.

Dintrusion

An intrusion policy focuses on detecting individual malicious activities or known attack patterns within single traffic flows, not on aggregating multiple connection initiation events over a time window to identify suspicious behavior.

Concept tested: Cisco FMC correlation policy functionality

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/policy_types.html

Topics

#Cisco FTD#Cisco FMC#Correlation Policy#Security Policies

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice