300-740 · Question #52
Which web application firewall deployment in the Cisco Secure DDoS protects against application layer and volumetric attacks?
The correct answer is C. Always-on. Always-on deployment keeps WAF protection continuously active in the traffic path, meaning it inspects and mitigates both volumetric attacks (flood-based) and application layer (L7) attacks like HTTP floods or SQL injection in real time without any activation delay - making it…
Question
Which web application firewall deployment in the Cisco Secure DDoS protects against application layer and volumetric attacks?
Options
- AHybrid
- BOn-demand
- CAlways-on
- DActive/passive
How the community answered
(23 responses)- A4% (1)
- C91% (21)
- D4% (1)
Explanation
Always-on deployment keeps WAF protection continuously active in the traffic path, meaning it inspects and mitigates both volumetric attacks (flood-based) and application layer (L7) attacks like HTTP floods or SQL injection in real time without any activation delay - making it the only mode that covers both threat categories simultaneously.
Why the distractors are wrong:
- A. Hybrid refers to a combination of on-premises and cloud-based scrubbing, describing where protection runs, not when - it doesn't guarantee continuous dual-layer coverage by itself.
- B. On-demand only activates protection when an attack is detected or manually triggered, so application layer attacks that ramp up gradually can slip through before mitigation kicks in.
- D. Active/passive is a high-availability failover concept (one node handles traffic while another stands by), not a DDoS deployment strategy - it addresses uptime, not attack type coverage.
Memory tip: Think "Always-on = always guarding both doors." Because it never sleeps, it can stand at both the volume gate (L3/L4) and the application gate (L7) simultaneously - unlike on-demand, which has to wake up first.
Topics
Community Discussion
No community discussion yet for this question.