300-710 · Question #444
Which Cisco Rapid Threat Containment mitigation action is enabled by integrating pxGrid Adaptive Network Control with Cisco ISE and Cisco Secure Firewall Management Center?
Integrating pxGrid Adaptive Network Control with Cisco ISE and Cisco Secure Firewall Management Center enables the 'block' mitigation action for Rapid Threat Containment.
Question
Which Cisco Rapid Threat Containment mitigation action is enabled by integrating pxGrid Adaptive Network Control with Cisco ISE and Cisco Secure Firewall Management Center?
Options
- Areject
- Bsuspend
- Cterminate
- Dblock
Why each option
Integrating pxGrid Adaptive Network Control with Cisco ISE and Cisco Secure Firewall Management Center enables the 'block' mitigation action for Rapid Threat Containment.
'Reject' is not a specific, named mitigation action directly enabled by this integration in the context of ANC policies, although it conveys a similar outcome to blocking network access.
'Suspend' implies a temporary pause or isolation, which might be an effect of blocking, but 'block' is the direct and specific mitigation action provided for network access control.
'Terminate' typically refers to ending a connection or session; however, the primary mitigation action for network access control in this integration is to 'block' future or ongoing network access for a compromised endpoint.
Concept tested: Cisco Rapid Threat Containment with pxGrid
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/device-management-and-troubleshooting.html#ID-2309-000000d0
Topics
Community Discussion
No community discussion yet for this question.