nerdexam
Cisco

300-740 · Question #52

Which web application firewall deployment in the Cisco Secure DDoS protects against application layer and volumetric attacks?

The correct answer is C. Always-on. Always-on deployment keeps WAF protection continuously active in the traffic path, meaning it inspects and mitigates both volumetric attacks (flood-based) and application layer (L7) attacks like HTTP floods or SQL injection in real time without any activation delay - making it…

Application and Data Security

Question

Which web application firewall deployment in the Cisco Secure DDoS protects against application layer and volumetric attacks?

Options

  • AHybrid
  • BOn-demand
  • CAlways-on
  • DActive/passive

How the community answered

(23 responses)
  • A
    4% (1)
  • C
    91% (21)
  • D
    4% (1)

Explanation

Always-on deployment keeps WAF protection continuously active in the traffic path, meaning it inspects and mitigates both volumetric attacks (flood-based) and application layer (L7) attacks like HTTP floods or SQL injection in real time without any activation delay - making it the only mode that covers both threat categories simultaneously.

Why the distractors are wrong:

  • A. Hybrid refers to a combination of on-premises and cloud-based scrubbing, describing where protection runs, not when - it doesn't guarantee continuous dual-layer coverage by itself.
  • B. On-demand only activates protection when an attack is detected or manually triggered, so application layer attacks that ramp up gradually can slip through before mitigation kicks in.
  • D. Active/passive is a high-availability failover concept (one node handles traffic while another stands by), not a DDoS deployment strategy - it addresses uptime, not attack type coverage.

Memory tip: Think "Always-on = always guarding both doors." Because it never sleeps, it can stand at both the volume gate (L3/L4) and the application gate (L7) simultaneously - unlike on-demand, which has to wake up first.

Topics

#DDoS Protection#Web Application Firewall#Deployment Modes#Cisco Secure DDoS

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice