QuestionQ2

Integration

An organization has deployed Cisco Firepower without IPS capabilities and now wants to enable traffic inspection. It must detect protocol anomalies and use Snort rule sets to identify malicious behavior. How can this be achieved?

  • A Modify the network discovery policy to detect new hosts to inspect.
  • B Modify the access control policy to redirect interesting traffic to the engine.
  • C Modify the intrusion policy to determine the minimum severity of an event to inspect.
  • D Modify the network analysis policy to process the packets for inspection.
Explanation

A network analysis policy governs packet decoding and preprocessing for inspection, including traffic normalization and identification of protocol anomalies. That preprocessing prepares traffic for evaluation by Snort intrusion rules, which detect malicious patterns.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!