300-710 · Question #396
An engineer must configure an inline set on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. The inline set must make a copy of each packet before analyzing the packet and…
The correct answer is D. Implement Strict TCP Enforcement. The scenario describes a need for blocking any connections that do not complete the three-way handshake. This behavior is associated with TCP session validation - ensuring that only legitimate sessions (with completed handshakes) are allowed. Implement Strict TCP Enforcement…
Question
An engineer must configure an inline set on a Cisco Secure IPS by using the Cisco Secure Firewall Management Center. The inline set must make a copy of each packet before analyzing the packet and block any connections that do not complete the three-way handshake. These configurations have been performed already:
- Select and enable the interfaces that will be added to the inline
set.
- Configure the speed and duplex.
- Configure the inline set and add the interfaces to the inline set.
Which action completes the task?
Options
- ASet Tap Mode to Inline.
- BConfigure Snort Fail Open.
- CConfigure Link State Propagation.
- DImplement Strict TCP Enforcement.
How the community answered
(69 responses)- A13% (9)
- B7% (5)
- C3% (2)
- D77% (53)
Explanation
The scenario describes a need for blocking any connections that do not complete the three-way handshake. This behavior is associated with TCP session validation - ensuring that only legitimate sessions (with completed handshakes) are allowed. Implement Strict TCP Enforcement - This feature ensures that only fully established TCP sessions (with a proper 3-way handshake) are allowed, and sessions that fail to complete the handshake are blocked.
Topics
Community Discussion
No community discussion yet for this question.