Lecture 10 Pt. 3 Flashcards

1
Q

What does Cisco FTD combine?

A

Cisco ASA Firewall (traditional), Cisco Firepower (NGFW)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two main operating modes of Cisco NGFW and Cisco NGIPS? i______ & ________e

A

Inline and passive (monitoring) mode

Inline mode is used for prevention, while passive mode is for monitoring traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of inline mode in Cisco NGFW and Cisco NGIPS?

A

Used for prevention

Inline devices can block and mitigate threats by being placed between communicating assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What happens during a software failure in inline mode?

A

All traffic is dropped

The fail-open or fail-to-wire capability can be used to allow traffic to bypass the device rules to avoid traffic loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What should fail-open not be used for?

A

When the security policy requires traffic to be inspected and accounted for (e.g. You would never enable it if the policy may choose to block some traffic)

Enabling open would allow traffic to bypass device rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an inline pair with a tap configured for?

A

To have two physical interfaces internally bridged

This setup allows for full Snort engine checks on a copy of the actual traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What traditional firewall features are not available for flows going through an inline pair?

A

NAT, routing, and ACLs

These features are not applicable in the inline pair configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Passive mode in Cisco’s NGFW or NGIPS is used to silently inspect _______ and ________ malicious activity without interrupting _______ flow

What is passive mode in Cisco NGFW or NGIPS used for?

A

traffic; identify; traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What can the device in passive mode do regarding malicious connections?

A

Reset malicious connections

However, this should not be considered a mitigation mechanism.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the most important capabilities of Cisco Firepower NGIPS (4)?

A

Threat containment and remediation, application visibility, identity management, security automation,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does high availability and stacking provide in Cisco Firepower NGIPS?

A

Redundancy and performance

This is achieved by leveraging multiple devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does network behavioral analysis help analysts with?

A

Prioritize and recover from attacks

It uses key behavioral indicators and threat scores.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Fill in the blank: Cisco Firepower NGIPS offers _______ inspection and control for better efficacy.

A

deep

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: Passive mode is only supported in routed deployment mode.

A

False

Passive mode is supported in both routed and transparent deployment modes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cisco ASA provides traditional firewall services such as (3)

A

Stateful firewalling, VPN, NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Cisco Firepower is a NGFW that provides more advanced features such as (5)

A

Application Visibility & Control
IPS/IDS
Threat Intelligence Blocking
Malware/File Blocking
Network Discovery

17
Q

What are the most important capabilities of Cisco Firepower NGIPS (5)?

A

logging and traceability management, high availability and stacking, network behavioral analysis, access control and segmentation, real-time contextual awareness