nerdexam
Cisco

300-710 · Question #84

The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the polici

The correct answer is B. drop packet. In Cisco FMC intrusion policies, each rule can be set to one of several actions. 'Drop and generate event' drops the packet AND logs an event - causing the flood of low-priority entries in the dashboard. Changing the action to 'Drop packet' drops the offending traffic silently wi

Configuration

Question

The event dashboard within the Cisco FMC has been inundated with low priority intrusion drop events, which are overshadowing high priority events. An engineer has been tasked with reviewing the policies and reducing the low priority events. Which action should be configured to accomplish this task?

Options

  • Agenerate events
  • Bdrop packet
  • Cdrop connection
  • Ddrop and generate

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    83% (48)
  • C
    5% (3)
  • D
    9% (5)

Explanation

In Cisco FMC intrusion policies, each rule can be set to one of several actions. 'Drop and generate event' drops the packet AND logs an event - causing the flood of low-priority entries in the dashboard. Changing the action to 'Drop packet' drops the offending traffic silently without generating an event log entry, reducing dashboard noise while still enforcing the security policy. 'Generate events' only logs without dropping. 'Drop connection' terminates the full TCP session. Using 'Drop packet' for noisy, low-priority rules suppresses their events while maintaining protection.

Topics

#FMC#Intrusion Policy#IPS Actions#Event Tuning

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice