350-201 exam dumps

350-201 practice question 123 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 123

Select 3

Your organization has implemented Cisco Secure Firewall to monitor and block malicious traffic. Recently, a legitimate application has been flagged as malicious by the intrusion prevention system (IPS), causing disruptions. How should you address this issue while maintaining a strong security posture?

  1. A

    Create a custom IPS rule to whitelist the application's traffic based on its unique attributes.

  2. B

    Disable the IPS module to prevent further disruptions to legitimate traffic.

  3. C

    Modify the existing IPS rules to exclude the specific traffic patterns associated with the legitimate application.

  4. D

    Analyze the application traffic further, then implement a more granular policy to allow its traffic while blocking actual threats.

  5. E

    Ignore the IPS alert, as the application is known to be safe.

Show answer and explanation

Correct answers: A, C, D

Explanation

When tuning or adapting devices and software, it is critical to address false positives without reducing the overall security posture. Creating custom rules, modifying existing rules, and implementing granular policies are all effective approaches to maintaining a balance between functionality and security. Disabling security modules or ignoring alerts, on the other hand, compromises the organization's network defenses and increases the risk of successful attacks.

  • A. Correct.

    Creating a custom IPS rule allows you to specifically whitelist the legitimate application's traffic without compromising the security posture for other traffic.

  • B. Incorrect.

    Disabling the IPS module is not recommended as it would leave the network vulnerable to actual threats.

  • C. Correct.

    Modifying the existing IPS rules to exclude the specific traffic patterns ensures that the legitimate application is not flagged while still enforcing other security measures.

  • D. Correct.

    Analyzing the application traffic and implementing a granular policy ensures a balance between security and functionality by allowing legitimate application traffic and blocking malicious traffic.

  • E. Incorrect.

    Ignoring the IPS alert is risky, as it could lead to a failure to detect actual threats if the application's behavior changes or if assumptions are incorrect.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam