300-710 · Question #405
An engineer must configure a correlation policy in Cisco Secure Firewall Management Center to detect when an IP address from an internal network communicates with a known malicious host. Connections…
The correct answer is C. connection tracker. To detect when internal IP addresses initiate connections to known malicious hosts using an external dynamic list, the engineer must configure a connection tracker event in the correlation policy. This allows the policy to monitor traffic flows and correlate them with the…
Question
An engineer must configure a correlation policy in Cisco Secure Firewall Management Center to detect when an IP address from an internal network communicates with a known malicious host. Connections made by the internalIP addresses must be tracked, and an external dynamic list must be used for the condition. Which type of event must the engineer configure on the correlation policy?
Options
- Anetwork discovery
- Bmalware
- Cconnection tracker
- DIntrusion Impact Alert
How the community answered
(53 responses)- A4% (2)
- B11% (6)
- C77% (41)
- D8% (4)
Explanation
To detect when internal IP addresses initiate connections to known malicious hosts using an external dynamic list, the engineer must configure a connection tracker event in the correlation policy. This allows the policy to monitor traffic flows and correlate them with the external threat intelligence source.
Topics
Community Discussion
No community discussion yet for this question.