350-401 Question 289
Select 3An enterprise network administrator is tasked with implementing threat defense mechanisms on the company’s network. The administrator decides to use Cisco Firepower Threat Defense (FTD) to protect against advanced threats. Which features of Cisco FTD can be used to achieve this objective?
- A
Intrusion Prevention System (IPS)
- B
Advanced Malware Protection (AMP)
- C
Quality of Service (QoS) traffic shaping
- D
URL Filtering
- E
Dynamic Host Configuration Protocol (DHCP) server functionality
Show answer and explanation
Correct answers: A, B, D
Explanation
Cisco Firepower Threat Defense (FTD) is a comprehensive solution that integrates multiple threat defense features, including Intrusion Prevention System (IPS) for detecting and stopping network-based attacks, Advanced Malware Protection (AMP) for identifying and preventing malware, and URL Filtering for blocking access to malicious or harmful websites. These features collectively protect the enterprise network from advanced threats. QoS and DHCP functionalities, while important for network operations, are not part of FTD's threat defense capabilities.
- A. Correct.
Intrusion Prevention System (IPS) is a core feature of Cisco Firepower Threat Defense (FTD) that allows for real-time detection and prevention of threats by analyzing network traffic.
- B. Correct.
Advanced Malware Protection (AMP) is a key feature of Cisco FTD used to detect and block malicious files and malware in the network.
- C. Incorrect.
Quality of Service (QoS) traffic shaping is a network performance optimization feature and is not a threat defense mechanism.
- D. Correct.
URL Filtering is part of Cisco FTD's threat defense capabilities, allowing administrators to block access to malicious or inappropriate websites.
- E. Incorrect.
Dynamic Host Configuration Protocol (DHCP) server functionality is used for IP address allocation and is not related to threat defense.