exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 120 discussion

Actual exam question from Cisco's 300-710
Question #: 120
Topic #: 1
[All 300-710 Questions]

A network engineer is tasked with minimizing traffic interruption during peak traffic times. When the SNORT inspection engine is overwhelmed, what must be configured to alleviate this issue?

  • A. Enable IPS inline link state propagation
  • B. Enable Pre-filter policies before the SNORT engine failure
  • C. Set a Trust ALL access control policy
  • D. Enable Automatic Application Bypass
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pr0fectus
6 months, 3 weeks ago
Selected Answer: D
Enabling AAB - if the Snort processes are causing a performance degradation, certain traffic can bypass these Snort processes to alleviate the bottleneck when a performance threshold is crossed.
upvoted 3 times
...
tanri04
1 year, 1 month ago
When the SNORT inspection engine is overwhelmed, to minimize traffic interruption during peak traffic times, a network engineer can configure the IPS (Intrusion Prevention System) to alleviate this issue by enabling Automatic Application Bypass. Therefore, the correct answer is D, Enable Automatic Application Bypass. When the SNORT inspection engine is overwhelmed, enabling Automatic Application Bypass allows the IPS to bypass specific applications or protocols that are causing the bottleneck. This ensures that critical traffic is not dropped, and network performance is not degraded during peak traffic times. Enabling IPS inline link state propagation (Option A) is a mechanism that ensures link state information is propagated to the inline security device, such as IPS. It helps ensure that the IPS does not forward traffic to an interface that is down. However, it does not directly address the issue of SNORT engine overload.
upvoted 4 times
...
Doris8000
2 years, 7 months ago
Automatic Application Bypass (AAB) allows packets to bypass detection if Snort is down or if a packet takes too long to process. AAB causes Snort to restart within ten minutes of the failure, and generates troubleshooting data that can be analyzed to investigate the cause of the Snort failure. https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/device_management_basics.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago