Which two deployment model configurations are supported for Cisco FTDv in AWS? (Choose two.)
Correct Answer: A,E
Question 602
Refer to the exhibit. What are two indications of the Cisco Firepower Services Module configuration? (Choose two.)
Correct Answer: A,E
sfr {fail-open | fail-close [monitor-only]} <- There's a couple different options here. The first one is fail-open which means that if the Firepower software module is unavailable, the ASA will continue to forward traffic. fail-close means that if the Firepower module fails, the traffic will stop flowing. While this doesn't seem ideal, there might be a use case for it when securing highly regulated environments. The monitor-only switch can be used with both and basically puts the Firepower services into IDS-mode only. This might be useful for initial testing or setup.
Question 603
Which two features of Cisco Email Security can protect your organization against email threats? (Choose two)
Which attack is preventable by Cisco Secure Email Gateway but not by the Cisco WSA?
Correct Answer: D
The following are the benefits of deploying Cisco Advanced Phishing Protection on the Cisco Email Security Gateway: Prevents the following: + Attacks that use compromised accounts and social engineering. + Phishing, ransomware, zero-day attacks and spoofing. + BEC with no malicious payload or URL. Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa13- 5/user_guide/b_ESA_Admin_Guide_13-5/m_advanced_phishing_protection.html
Question 605
What is a characteristic of an EDR solution and not of an EPP solution?
Correct Answer: B
EDR stands for endpoint detection and response, while EPP stands for endpoint protection platform. EDR and EPP are two types of endpoint security solutions that have different capabilities and objectives. EDR provides real-time visibility into endpoint activities, detects malicious behavior and anomalies, and enables security teams to investigate and respond to threats. EPP prevents, detects, and remediates security threats on endpoints, such as known and unknown malware, ransomware, and zero-day vulnerabilities. EPP solutions may also include EDR capabilities, but not all EDR solutions include EPP capabilities. One of the key features of EDR is retrospective analysis, which means the ability to look back at historical endpoint data and identify the root cause, scope, and impact of a security incident. Retrospective analysis helps security teams understand how the threat entered the network, what actions it performed, and how to prevent it from happening again. EPP solutions, on the other hand, do not provide retrospective analysis, as they are mainly focused on preventing and remediating threats, rather than investigating and responding to them. Therefore, the correct answer is B. Retrospective analysis is a characteristic of an EDR solution and not of an EPP solution. References: EPP vs. EDR: Why You Need Both - CrowdStrike EDR vs EPP: What is the Difference? - Exabeam Understanding MDR, EDR, EPP, and XDR | Netsurion EDR vs EPP: Key Features, Differences, and How They Work Together Endpoint Security Tools: EPP vs EDR | Prey Blog