Q: 5
A network engineer must configure IPS mode on a Cisco Secure firewall Threat Defense device to
inspect traffic and act as an IDS. The engineer already configured the passive-interface on the secure
firewall threat Defence device and SPAN on the switch. What must be configured next by the
engineer?
Options
Discussion
I think it needs to be A. Since the passive-interface and SPAN are already done, the FTD is getting a copy of the traffic. But unless you set up an intrusion policy, nothing gets inspected for threats. Not 100% but matches what I've seen in labs. Anyone disagree?
A for sure. You already set up the passive-interface and SPAN, so the next step is to actually apply an intrusion policy on the FTD to start inspecting for threats. Pretty sure that's what Cisco expects.
B or D? Not sure, but I think you need an active interface or SPAN port to monitor traffic. If anyone knows for sure, let me know.
Be respectful. No spam.