exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 154 discussion

Actual exam question from Cisco's 300-710
Question #: 154
Topic #: 1
[All 300-710 Questions]

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?

  • A. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option.
  • B. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option.
  • C. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option.
  • D. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1 week, 1 day ago
Selected Answer: D
Another messed up wording. With all these fancy names let's FTD is FTD, no such a button in the menu says "Oh I'm an IPS!" or "OH Now I'm a bloody IDS!" You make it an IDS by unchecking "drop when inline", so D.
upvoted 1 times
3 weeks ago
Selected Answer: B
First of all, it won't make any sense to do anything "when inline" when it comes to an IDP, because an IDS is not inline. The B answer is that if option "Drop when inline" is Disabled, SNORT rules are evaluated for that flow and it will mark the result, without impacting traffic, as it would have taken the action on it. https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/214609-firepower-data-path-troubleshooting-phas.html This is why I am sticking with B
upvoted 1 times
2 months ago
Selected Answer: D
I think it is D because of the statement in the question “not block the suspicious traffic”.
upvoted 2 times
6 months, 1 week ago
Let me rephrase each option: A. checking the “Drop when inline” option configures the system in IPS mode B. unchecking the “Drop when inline” option configures the system in IPS mode C. checking the “Drop when inline” option configures the system in IDS mode D. unchecking the “Drop when inline” option configures the system in IDS mode
upvoted 1 times
6 months, 1 week ago
option A itself is correct but does not meet the question's requirement. option B is wrong. option C is wrong. option D is correct and meets the question's requirement.
upvoted 2 times
9 months, 2 weeks ago
Selected Answer: D
Curse Cisco and their semantic pitfalls. I think you start with a neutral inspection policy. Then, the keyword is "by": By unchecking "drop when inline" in the inspection policy, you create an IDS policy, instead of an IPS policy. So I choose D But that could be wrong, depending on how Cisco want to interpret things...
upvoted 4 times
1 year ago
Selected Answer: B
The official name of the policy is IPS. You then uncheck "drop when inline" to make it function as IDS.
upvoted 3 times
1 year, 1 month ago
Selected Answer: B
i think B is correct, since the cisco terminology, there's not IDS deployment, only IPS deployment for FTD. https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_intrusion_policies.html?bookSearch=true#concept_D1F1CDE29BDE4ACF9F254D8E5F1D518D Also the option of drop does exist too, have to be unchecked: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_intrusion_policies.html?bookSearch=true#ID-2231-0000003d
upvoted 2 times
1 year, 2 months ago
IDS = Intrusion Detection System IPS = Intrusion Prevention System Doesn't this ^ pretty much say it all? One detects and one prevents. This is a classic example of a Cisco trip-you-up question. Its purpose is not to test whether or not you know and understand a concept. No...it's purpose is to present you with designed, indecipherable ambiguity in an effort to collect another $300.
upvoted 2 times
1 year, 3 months ago
Welcome to Cisco Trivia Game where each Game cost $300! I think its D because we are creating an IDS behaving policy by deselecting drop when inline option on the policy. Semantics are making Cisco too much money. I don't know if its technically called IDS or still IPS mode when you disable the drop when selected checkbox? I cannot find a definitive documentation that calls it out.
upvoted 4 times
1 year, 2 months ago
I would go for the IDS > unchecking...but then I saw the question ...it is definatley IPS > unchecking ....Cisco questions - you have to love them ...then they wonder why we are going to examtopics :)
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago