nerdexam
Cisco

500-220 · Question #48

Refer to the exhibit. Which IDS/IPS mode is the MX Security Appliance configured for?

The correct answer is B. prevention. Prevention mode means the MX Security Appliance is operating as an IPS (Intrusion Prevention System), actively inspecting traffic and blocking malicious packets in real time - not just alerting on them. The exhibit likely shows the toggle or dropdown set to "Prevention" in the…

Cisco Meraki Security and SD-WAN Solutions

Question

Refer to the exhibit. Which IDS/IPS mode is the MX Security Appliance configured for?

Exhibit

500-220 question #48 exhibit

Options

  • Aquarantine
  • Bprevention
  • Cdetection
  • Dblocking

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    79% (37)
  • C
    2% (1)
  • D
    13% (6)

Explanation

Prevention mode means the MX Security Appliance is operating as an IPS (Intrusion Prevention System), actively inspecting traffic and blocking malicious packets in real time - not just alerting on them. The exhibit likely shows the toggle or dropdown set to "Prevention" in the Meraki dashboard under Security & SD-WAN > Threat Protection.

Why the distractors are wrong:

  • C (Detection) is the other valid mode (IDS), but it only alerts on threats without stopping them - traffic still passes through.
  • D (Blocking) sounds plausible but is not the actual label Meraki uses; "Prevention" is the correct Meraki terminology for active blocking.
  • A (Quarantine) is not an IDS/IPS mode at all - it's an endpoint/NAC concept unrelated to MX inline traffic inspection.

Memory tip: Think P for Prevention = Police (stops the threat), D for Detection = Detective (spots the threat but doesn't stop it). On the Meraki MX, if you want the appliance to act, choose Prevention.

Topics

#IDS/IPS Modes#MX Security Appliance#Threat Prevention#Security Configuration

Community Discussion

No community discussion yet for this question.

Full 500-220 Practice