300-710 · Question #380
An engineer must deploy a Cisco Secure Firewall Threat Defense instance. The company wants the Secure Firewall Threat Defense deployment to allow business traffic in the event of any type of…
The correct answer is B. Snort fail open. The Snort fail open mode is used in Cisco Secure Firewall Threat Defense to ensure that business traffic is allowed to pass through the firewall even if there is a failure in the IPS functionality. This is particularly useful when an organization prioritizes uninterrupted…
Question
An engineer must deploy a Cisco Secure Firewall Threat Defense instance. The company wants the Secure Firewall Threat Defense deployment to allow business traffic in the event of any type of failure, and there must be no connectivity issues caused by the IPS in the perimeter of its data center. Which implementation mode must the engineer use?
Options
- Ahardware bypass
- BSnort fail open
- Cinline set
- Dpassive
How the community answered
(35 responses)- A3% (1)
- B77% (27)
- C14% (5)
- D6% (2)
Explanation
The Snort fail open mode is used in Cisco Secure Firewall Threat Defense to ensure that business traffic is allowed to pass through the firewall even if there is a failure in the IPS functionality. This is particularly useful when an organization prioritizes uninterrupted traffic flow over security inspection during failures. When Snort (the intrusion prevention system) fails or becomes unavailable, fail-open mode bypasses the IPS processing, ensuring that legitimate business traffic continues to flow without
Topics
Community Discussion
No community discussion yet for this question.