350-401 exam dumps

350-401 practice question 290 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 290

Single answer

A network administrator has deployed Cisco Firepower Threat Defense (FTD) to protect their enterprise network. During a post-deployment review, they notice that certain types of malicious traffic are not being blocked despite matching configured intrusion policies. What could be the most likely reason for this behavior?

  1. A

    The intrusion policy has not been assigned to the access control policy.

  2. B

    The Firepower Threat Defense device has outdated signatures.

  3. C

    The Security Intelligence feature is disabled on the FTD device.

  4. D

    The traffic is being permitted by a higher-priority rule in the access control policy.

Show answer and explanation

Correct answer: A

Explanation

In Cisco Firepower Threat Defense (FTD), intrusion policies are used to detect and block malicious traffic. However, these policies must be explicitly assigned to the access control policy for them to take effect. If the intrusion policy is not assigned, the FTD device will not enforce the intrusion detection rules, resulting in malicious traffic being allowed through.

  • A. Correct.

    The intrusion policy must be explicitly assigned to the access control policy in order for it to take effect. Without this assignment, malicious traffic matching the intrusion policy will not be blocked.

  • B. Incorrect.

    While outdated signatures can reduce the effectiveness of threat detection, they do not directly prevent the FTD device from blocking traffic if the intrusion policy is correctly configured and applied.

  • C. Incorrect.

    Disabling Security Intelligence would impact threat detection based on IP reputation but does not affect the functionality of intrusion policies.

  • D. Incorrect.

    Although higher-priority rules in the access control policy can allow traffic, this is unrelated to whether the intrusion policy is applied to the access control policy.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam