exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 154 discussion

Actual exam question from Cisco's 300-710
Question #: 154
Topic #: 1
[All 300-710 Questions]

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?

  • A. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option.
  • B. Configure IPS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option.
  • C. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by checking the “Drop when inline” option.
  • D. Configure IDS mode when creating or editing a policy rule under the Cisco FMC Intrusion tab in Access Policies section by unchecking the “Drop when inline” option.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tinyJoe
4 weeks ago
Selected Answer: D
I think it is D because of the statement in the question “not block the suspicious traffic”.
upvoted 2 times
...
Stevens0103
5 months ago
Let me rephrase each option: A. checking the “Drop when inline” option configures the system in IPS mode B. unchecking the “Drop when inline” option configures the system in IPS mode C. checking the “Drop when inline” option configures the system in IDS mode D. unchecking the “Drop when inline” option configures the system in IDS mode
upvoted 1 times
Stevens0103
5 months ago
option A itself is correct but does not meet the question's requirement. option B is wrong. option C is wrong. option D is correct and meets the question's requirement.
upvoted 2 times
...
...
z6st2a1jv
8 months, 1 week ago
Selected Answer: D
Curse Cisco and their semantic pitfalls. I think you start with a neutral inspection policy. Then, the keyword is "by": By unchecking "drop when inline" in the inspection policy, you create an IDS policy, instead of an IPS policy. So I choose D But that could be wrong, depending on how Cisco want to interpret things...
upvoted 3 times
...
bassfunk
11 months, 2 weeks ago
Selected Answer: B
The official name of the policy is IPS. You then uncheck "drop when inline" to make it function as IDS.
upvoted 2 times
...
Dreng65
1 year ago
Selected Answer: B
i think B is correct, since the cisco terminology, there's not IDS deployment, only IPS deployment for FTD. https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_intrusion_policies.html?bookSearch=true#concept_D1F1CDE29BDE4ACF9F254D8E5F1D518D Also the option of drop does exist too, have to be unchecked: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/getting_started_with_intrusion_policies.html?bookSearch=true#ID-2231-0000003d
upvoted 2 times
...
trudint
1 year, 1 month ago
IDS = Intrusion Detection System IPS = Intrusion Prevention System Doesn't this ^ pretty much say it all? One detects and one prevents. This is a classic example of a Cisco trip-you-up question. Its purpose is not to test whether or not you know and understand a concept. No...it's purpose is to present you with designed, indecipherable ambiguity in an effort to collect another $300.
upvoted 2 times
...
THEODORABLE
1 year, 2 months ago
Welcome to Cisco Trivia Game where each Game cost $300! I think its D because we are creating an IDS behaving policy by deselecting drop when inline option on the policy. Semantics are making Cisco too much money. I don't know if its technically called IDS or still IPS mode when you disable the drop when selected checkbox? I cannot find a definitive documentation that calls it out.
upvoted 4 times
Bbb78
1 year, 1 month ago
I would go for the IDS > unchecking...but then I saw the question ...it is definatley IPS > unchecking ....Cisco questions - you have to love them ...then they wonder why we are going to examtopics :)
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago