300-415 Question 218
Select 3An organization is deploying Cisco SD-WAN and wants to enable Intrusion Prevention System (IPS) capabilities as part of their security policies. They want to ensure that IPS is applied to traffic between branch sites and the data center. Which of the following steps are required to successfully configure IPS in the Cisco SD-WAN solution?
- A
Enable the IPS feature on the vSmart controller.
- B
Attach an IPS policy to the centralized data policy in vManage.
- C
Ensure the devices where IPS is applied are running the security feature license.
- D
Enable IPS within the zone-based firewall configuration.
- E
Download and update the Cisco Talos signature database on the relevant devices.
Show answer and explanation
Correct answers: B, C, E
Explanation
To configure IPS in Cisco SD-WAN, you need to attach the IPS policy to a centralized data policy to define which traffic it applies to. The devices enforcing IPS must have the security feature license enabled. Additionally, the Cisco Talos signature database must be regularly updated on the devices to ensure accurate threat detection. Zone-based firewalls are not a requirement for IPS, and configuration is managed through vManage, not vSmart.
- A. Incorrect.
The IPS feature is not enabled on the vSmart controller. Instead, it is applied at the edge devices using vManage policies.
- B. Correct.
Attaching an IPS policy to the centralized data policy ensures that the IPS rules are applied to the relevant traffic.
- C. Correct.
Devices applying IPS must have the security feature license enabled to support the functionality.
- D. Incorrect.
IPS configuration does not require enabling zone-based firewall. IPS is a separate feature that works outside of zone-based firewall settings.
- E. Correct.
The Cisco Talos signature database must be downloaded and updated on the devices to ensure IPS operates with the latest threat intelligence.