350-201 exam dumps

350-201 practice question 110 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 110

Select 3

You are configuring a Cisco Firepower Threat Defense (FTD) device to secure a corporate network. The network contains sensitive data and must be protected from known threats while also being monitored for suspicious activity. Which combination of features would best meet these requirements?

  1. A

    Access Control Policies

  2. B

    Intrusion Prevention System (IPS)

  3. C

    SSL Decryption

  4. D

    Network Address Translation (NAT)

  5. E

    Security Intelligence (SI) Blocking

Show answer and explanation

Correct answers: A, B, E

Explanation

To secure a network containing sensitive data, it is crucial to implement Access Control Policies to manage traffic, an Intrusion Prevention System (IPS) to detect and block threats, and Security Intelligence (SI) Blocking to preemptively stop traffic from known malicious sources. These features together provide robust protection and monitoring for the network.

  • A. Correct.

    Access Control Policies are essential for defining which traffic is allowed or denied based on configured rules. This helps in segmenting and protecting the network from unauthorized access.

  • B. Correct.

    An Intrusion Prevention System (IPS) is critical for identifying and preventing known and emerging threats by analyzing traffic for malicious signatures or behaviors.

  • C. Incorrect.

    SSL Decryption is used for inspecting encrypted traffic but is not mandatory for this scenario as it is not explicitly mentioned that encrypted traffic inspection is required.

  • D. Incorrect.

    Network Address Translation (NAT) is useful for hiding internal IP addresses but does not directly contribute to threat detection or prevention in this context.

  • E. Correct.

    Security Intelligence (SI) Blocking allows you to block traffic from known malicious IP addresses, domains, or URLs, which is vital for protecting sensitive data and mitigating threats.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam