Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

An organization is deploying a Cisco Firepower Threat Defense (FTD) appliance and needs to define custom application signatures to accurately identify and control a proprietary internal application that uses a unique protocol header. Which configuration element within Firepower Management Center (FMC) allows for the creation of these custom application identities?

  1. ANetwork Analysis Policy (NAP)
  2. BIntrusion Policy
  3. CSecurity Intelligence Feed
  4. DApplication Detector
Show answer & explanation

Correct answer: D. Application Detector

The Application Detector within Firepower Management Center (FMC) is the component used to create and manage custom application identifiers. This allows FTD to recognize proprietary applications based on unique characteristics like protocol headers, enabling granular control in access policies.

Why the other options are wrong

  • A. A Network Analysis Policy (NAP) defines how Firepower analyzes network traffic for protocol compliance, anomalies, and vulnerabilities, but it's not for creating new application identities.
  • B. An Intrusion Policy defines how the system detects and prevents intrusions based on signatures and rules, distinct from identifying custom applications.
  • C. Security Intelligence Feeds are used to block known bad IPs, URLs, and domains based on external threat intelligence, not to define custom applications.

Cisco FTD Custom Application ID

The ability within Cisco Firepower Threat Defense (FTD) to define unique signatures for proprietary or unrecognized applications, enabling granular control.

  • Uses the Application Detector in FMC.
  • Identifies applications independent of port.
  • Crucial for controlling internal or niche applications.

Memory trick: Detect and define your own unique apps.

More Content Security questions