GSLC · Question #513
You are configuring IPS (Intrusion Prevention System) on a Cisco IOS router. The IPS Policy Wizard window opens when you confirm the SDEE messages. Which of the following tasks can you perform using…
The correct answer is A. Select the direction of traffic for inspecting the events. C. Select the interface for applying the IPS rule. D. Select the SDF file which a user can use. The Cisco SDM IPS Policy Wizard allows administrators to configure traffic direction, select the interface for the IPS rule, and specify the SDF signature file. Encryption configuration is a separate process not handled by this wizard.
Question
You are configuring IPS (Intrusion Prevention System) on a Cisco IOS router. The IPS Policy Wizard window opens when you confirm the SDEE messages. Which of the following tasks can you perform using the IPS Policy Wizard window? Each correct answer represents a complete solution. Choose all that apply.
Options
- ASelect the direction of traffic for inspecting the events.
- BSelect an encryption method to improve security.
- CSelect the interface for applying the IPS rule.
- DSelect the SDF file which a user can use.
How the community answered
(34 responses)- A91% (31)
- B9% (3)
Why each option
The Cisco SDM IPS Policy Wizard allows administrators to configure traffic direction, select the interface for the IPS rule, and specify the SDF signature file. Encryption configuration is a separate process not handled by this wizard.
The IPS Policy Wizard includes a dedicated step to choose whether IPS inspection is applied to inbound, outbound, or both directions of traffic on the selected interface.
Encryption method selection is not a function of the IPS Policy Wizard - encryption is configured independently through features such as IPsec or SSL/TLS, which are unrelated to signature-based IPS inspection.
Selecting which router interface the IPS rule will be bound to is a core step of the IPS Policy Wizard, as the rule must be associated with a specific interface to take effect.
The wizard prompts the administrator to specify the Signature Definition File (SDF) path, which contains the attack signatures the IPS engine uses to detect and prevent threats.
Concept tested: Cisco SDM IPS Policy Wizard configuration tasks
Source: https://www.cisco.com/c/en/us/td/docs/routers/access/interfaces/software/feature/guide/ips.html
Topics
Community Discussion
No community discussion yet for this question.