nerdexam
Cisco

300-710 · Question #396

An engineer must configure an inline set on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. The inline set must make a copy of each packet before analyzing the packet and…

The correct answer is D. Implement Strict TCP Enforcement. The scenario describes a need for blocking any connections that do not complete the three-way handshake. This behavior is associated with TCP session validation - ensuring that only legitimate sessions (with completed handshakes) are allowed. Implement Strict TCP Enforcement…

Configuration

Question

An engineer must configure an inline set on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. The inline set must make a copy of each packet before analyzing the packet and block any connections that do not complete the three-way handshake. These configurations have been performed already:

  • Select and enable the interfaces that will be added to the inline

set.

  • Configure the speed and duplex.
  • Configure the inline set and add the interfaces to the inline set.

Which action completes the task?

Options

  • ASet Tap Mode to Inline.
  • BConfigure Snort Fail Open.
  • CConfigure Link State Propagation.
  • DImplement Strict TCP Enforcement.

How the community answered

(69 responses)
  • A
    13% (9)
  • B
    7% (5)
  • C
    3% (2)
  • D
    77% (53)

Explanation

The scenario describes a need for blocking any connections that do not complete the three-way handshake. This behavior is associated with TCP session validation - ensuring that only legitimate sessions (with completed handshakes) are allowed. Implement Strict TCP Enforcement - This feature ensures that only fully established TCP sessions (with a proper 3-way handshake) are allowed, and sessions that fail to complete the handshake are blocked.

Topics

#Cisco Secure IPS#FMC#Inline Set#Strict TCP Enforcement

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice