NETSEC-PRO · Question #12
When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?
The correct answer is B. Configure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles. A comprehensive security approach uses: - User-ID for identity-based policies - App-ID for application-based security - Decryption to inspect encrypted traffic - Security profiles to enforce protections - Dynamic updates to ensure up-to-date threat coverage For comprehensive secu
Question
When configuring Security policies on VM-Series firewalls, which set of actions will ensure the most comprehensive Security policy enforcement?
Options
- AConfigure port-based policies, check threat logs weekly, conduct software updates annually, and
- BConfigure policies using User-ID and App-ID, enable decryption, apply appropriate security profiles
- CConfigure all default policies provided by the firewall, use Policy Optimizer, and adjust security
- DConfigure a block policy for all malicious inbound traffic, configure an allow policy for all outbound
How the community answered
(55 responses)- A5% (3)
- B78% (43)
- C4% (2)
- D13% (7)
Explanation
A comprehensive security approach uses: - User-ID for identity-based policies - App-ID for application-based security - Decryption to inspect encrypted traffic - Security profiles to enforce protections - Dynamic updates to ensure up-to-date threat coverage For comprehensive security, combine User-ID, App-ID, decryption, and security profiles. Keep the firewall updated with dynamic content updates to maintain the strongest security posture. This ensures real-time, identity-aware, and application-centric security enforcement.
Topics
Community Discussion
No community discussion yet for this question.