nerdexam
Cisco

300-710 · Question #405

An engineer must configure a correlation policy in Cisco Secure Firewall Management Center to detect when an IP address from an internal network communicates with a known malicious host. Connections…

The correct answer is C. connection tracker. To detect when internal IP addresses initiate connections to known malicious hosts using an external dynamic list, the engineer must configure a connection tracker event in the correlation policy. This allows the policy to monitor traffic flows and correlate them with the…

Configuration

Question

An engineer must configure a correlation policy in Cisco Secure Firewall Management Center to detect when an IP address from an internal network communicates with a known malicious host. Connections made by the internalIP addresses must be tracked, and an external dynamic list must be used for the condition. Which type of event must the engineer configure on the correlation policy?

Options

  • Anetwork discovery
  • Bmalware
  • Cconnection tracker
  • DIntrusion Impact Alert

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    11% (6)
  • C
    77% (41)
  • D
    8% (4)

Explanation

To detect when internal IP addresses initiate connections to known malicious hosts using an external dynamic list, the engineer must configure a connection tracker event in the correlation policy. This allows the policy to monitor traffic flows and correlate them with the external threat intelligence source.

Topics

#Cisco FMC#Correlation Policy#Connection Tracking#External Dynamic List

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice