exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 39 discussion

Actual exam question from Cisco's 300-710
Question #: 39
Topic #: 1
[All 300-710 Questions]

An engineer is building a new access control policy using Cisco FMC. The policy must inspect a unique IPS policy as well as log rule matching. Which action must be taken to meet these requirements?

  • A. Configure an IPS policy and enable per-rule logging
  • B. Disable the default IPS policy and enable global logging
  • C. Configure an IPS policy and enable global logging
  • D. Disable the default IPS policy and enable per-rule logging
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
14a1949
1 week, 2 days ago
Selected Answer: A
To meet the requirements of inspecting a unique IPS policy and logging rule matching in a new access control policy using Cisco FMC, the correct action is: A. Configure an IPS policy and enable per-rule logging. This approach ensures that each rule within the access control policy can be inspected with the specified IPS policy and that logging is enabled for each rule to track and log matching traffic Option C: Configure an IPS policy and enable global logging. This would apply the IPS policy and enable logging globally, but it might not provide the granularity needed for per-rule inspection and logging
upvoted 1 times
...
gc999
1 year ago
The policy must inspect a unique IPS policy as well as log "rule" matching, so does it mean the rule is IPS rule or Access Control Policy rule? I can only see logging option at Access Control Policy level. so should the answer "global" is more safe?
upvoted 1 times
...
Cokamaniako
1 year, 2 months ago
Selected Answer: A
"The policy must inspect a unique IPS policy as well as log rule matching" In each policy yo can enable logging for more traffic detail. You also can enable the logging in default policy Answer A
upvoted 2 times
...
Initial14
1 year, 3 months ago
Selected Answer: A
Only A
upvoted 1 times
...
Joe_Blue
1 year, 4 months ago
Selected Answer: A
To meet the requirements of inspecting a unique IPS policy as well as logging rule matching in a new access control policy using Cisco FMC, the engineer should configure an IPS policy and enable per-rule logging. Therefore, the correct answer is A: Configure an IPS policy and enable per-rule logging.
upvoted 2 times
...
matan24
1 year, 4 months ago
Selected Answer: A
as cewe said, "you can set logging per rule for an access control policy, so A is the right one"
upvoted 1 times
...
minon_bob
1 year, 7 months ago
Selected Answer: C
There is no per-rule logging on the system. Also there would be no need to log the ACL rule as an Intrusion event will cause the rule to generate an event.
upvoted 2 times
...
cryptofetti
2 years, 10 months ago
C, seems to make more sense here I do not think there is a setting to enable per-rule logging
upvoted 3 times
gwb
5 months ago
There is a per-rule logging. yeah C makes sense (global), but I will go with rule base (A)
upvoted 1 times
...
cewe
2 years, 4 months ago
you can set logging per rule for an access control policy, so A is the right one
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago