nerdexam
Cisco

300-710 · Question #49

Which description of a correlation, policy configuration in the Cisco Firepower Management Center, is true?

The correct answer is C. You cannot add a host profile qualification to a correlation rule that is triggered by a malware. In Cisco Firepower Management Center, a true statement regarding correlation policy configuration is that you cannot add a host profile qualification to a correlation rule that is triggered by a malware event.

Configuration

Question

Which description of a correlation, policy configuration in the Cisco Firepower Management Center, is true?

Options

  • ACorrelation policy priorities override whitelist priorities.
  • BThe system displays correlation policies that are created on all of the domains in a multidomain
  • CYou cannot add a host profile qualification to a correlation rule that is triggered by a malware
  • DDeleting a response group deletes the responses of that group.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    9% (2)
  • C
    73% (16)
  • D
    14% (3)

Why each option

In Cisco Firepower Management Center, a true statement regarding correlation policy configuration is that you cannot add a host profile qualification to a correlation rule that is triggered by a malware event.

ACorrelation policy priorities override whitelist priorities.

Correlation policy priorities determine the evaluation order of correlation rules and do not override whitelist priorities, which typically grant explicit permission for traffic regardless of other policy considerations.

BThe system displays correlation policies that are created on all of the domains in a multidomain

In a multidomain Firepower deployment, administrators usually only see correlation policies relevant to their assigned domain(s) for security and administrative isolation, not policies from all domains.

CYou cannot add a host profile qualification to a correlation rule that is triggered by a malwareCorrect

Cisco Firepower Management Center (FMC) correlation rules allow combining various event types and conditions. However, a specific design limitation prevents the direct addition of a host profile qualification-which characterizes a host's attributes like operating system or applications-to a correlation rule when that rule is primarily triggered by a malware event. Malware detection is fundamentally focused on the file's disposition, making host profile details less relevant as a direct trigger qualification for this specific event type in a correlation rule.

DDeleting a response group deletes the responses of that group.

Deleting a response group typically removes the group itself, but whether the associated individual responses are also deleted depends on their configuration and whether they are referenced elsewhere, making the statement not universally true without further context.

Concept tested: Cisco FMC correlation policy host profile limitations

Topics

#Correlation Policy#Firepower Management Center#Malware Event#Host Profile

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice