nerdexam
Cisco

350-701 · Question #54

Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?

The correct answer is D. network discovery. The network discovery policy on Cisco Firepower NGIPS is used to identify and collect detailed information about hosts, applications, and users on the network.

Submitted by chen.hong· Mar 30, 2026

Question

Which policy is used to capture host information on the Cisco Firepower Next Generation Intrusion Prevention System?

Exhibit

350-701 question #54 exhibit

Options

  • Acorrelation
  • Bintrusion
  • Caccess control
  • Dnetwork discovery

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    86% (32)

Why each option

The network discovery policy on Cisco Firepower NGIPS is used to identify and collect detailed information about hosts, applications, and users on the network.

Acorrelation

A correlation policy is used to identify patterns of events that might indicate a security incident, not to capture host information.

Bintrusion

An intrusion policy is used to detect and prevent malicious activity based on signatures and behavioral analysis, not to discover hosts.

Caccess control

An access control policy is used to define which traffic is allowed or blocked based on various criteria, not to capture host information.

Dnetwork discoveryCorrect

The network discovery policy is specifically designed to gather information about network assets, including hosts, operating systems, services, and applications, by passively analyzing network traffic to populate the host and network map.

Concept tested: Cisco Firepower Network Discovery Policy

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/6_2_1/configuration/guide/fpmc-config-guide-v621/network_discovery_policy.html

Topics

#Cisco Firepower#Network Discovery

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice