300-710 · Question #281
A security engineer must configure policies for a recently deployed Cisco FTD. The security policy for the company dictates that when five or more connections from external sources are initiated…
The correct answer is C. correlation. To generate an alert when five or more connections are initiated from external sources within 2 minutes, a correlation policy must be configured in Cisco FMC.
Question
A security engineer must configure policies for a recently deployed Cisco FTD. The security policy for the company dictates that when five or more connections from external sources are initiated within 2 minutes, there is cause for concern. Which type of policy must be configured in Cisco FMC to generate an alert when this condition is triggered?
Options
- Aapplication detector
- Baccess control
- Ccorrelation
- Dintrusion
How the community answered
(30 responses)- A3% (1)
- B7% (2)
- C80% (24)
- D10% (3)
Why each option
To generate an alert when five or more connections are initiated from external sources within 2 minutes, a correlation policy must be configured in Cisco FMC.
An application detector identifies applications but does not monitor the frequency or rate of connections over time to trigger alerts based on thresholds.
An access control policy permits or denies traffic based on rules, but it does not inherently monitor event frequency or generate alerts based on connection thresholds over time.
A correlation policy in Cisco FMC is specifically designed to analyze multiple security events over a defined time period and trigger an action, such as an alert, when specific conditions or patterns, like a high rate of connections from external sources, are met. This allows detection of complex, time-based threat indicators.
An intrusion policy focuses on detecting individual malicious activities or known attack patterns within single traffic flows, not on aggregating multiple connection initiation events over a time window to identify suspicious behavior.
Concept tested: Cisco FMC correlation policy functionality
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/policy_types.html
Topics
Community Discussion
No community discussion yet for this question.