300-710 · Question #93
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort r
The correct answer is B. Modify the access control policy to redirect interesting traffic to the engine.. A network analysis policy (NAP) governs how traffic is decoded and preprocessed so that it can be further evaluated, especially for anomalous traffic that might signal an intrusion attempt. To apply intrusion policies to network traffic, you select the policy within an access con
Question
An organization has implemented Cisco Firepower without IPS capabilities and now wants to enable inspection for their traffic. They need to be able to detect protocol anomalies and utilize the Snort rule sets to detect malicious behavior. How is this accomplished?
Options
- AModify the network discovery policy to detect new hosts to inspect.
- BModify the access control policy to redirect interesting traffic to the engine.
- CModify the intrusion policy to determine the minimum severity of an event to inspect.
- DModify the network analysis policy to process the packets for inspection.
How the community answered
(49 responses)- A8% (4)
- B71% (35)
- C16% (8)
- D4% (2)
Explanation
A network analysis policy (NAP) governs how traffic is decoded and preprocessed so that it can be further evaluated, especially for anomalous traffic that might signal an intrusion attempt. To apply intrusion policies to network traffic, you select the policy within an access control rule that allows traffic. You do not directly assign intrusion policies.
Topics
Community Discussion
No community discussion yet for this question.