ExamGecko
Question list
Search
Search

Related questions











Question 289 - 300-710 discussion

Report
Export

A network engineer must configure IPS mode on a Cisco Secure firewall Threat Defense device to inspect traffic and act as an IDS. The engineer already configured the passive-interface on the secure firewall threat Defence device and SPAN on the switch. What must be configured next by the engineer?

A.

intrusion policy on the Secure Firewall Threat Defense device

Answers
A.

intrusion policy on the Secure Firewall Threat Defense device

B.

active Interface on me Secure Firewall threat Defense device

Answers
B.

active Interface on me Secure Firewall threat Defense device

C.

DHCP on the switch

Answers
C.

DHCP on the switch

D.

active SPAN port on the switch

Answers
D.

active SPAN port on the switch

Suggested answer: A

Explanation:

To configure IPS mode on a Cisco Secure Firewall Threat Defense (FTD) device to inspect traffic and act as an IDS, the network engineer must configure an intrusion policy on the FTD device. The passive-interface and SPAN on the switch have already been configured, which means the traffic is being mirrored to the FTD. The next step is to set up an intrusion policy that defines the rules and actions for detecting and responding to malicious traffic.

Steps:

In FMC, navigate to Policies > Intrusion.

Create a new intrusion policy or edit an existing one.

Define the rules and actions for detecting threats.

Apply the intrusion policy to the relevant interfaces or access control policies.

This configuration enables the FTD to inspect the mirrored traffic and take appropriate actions based on the defined intrusion policy.

asked 07/10/2024
Michael Geary
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first