Cisco CCNP Security Core (SCOR) 350-701Content SecurityEasy
A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to protect internal users from malicious websites. The requirement is to block access to all gambling-related websites and generate an alert when a user attempts to access any site categorized as 'Adult.' Which content security feature should the engineer configure to meet these requirements?
- AURL Filtering policies
- BFile Policies
- CIntrusion Prevention System (IPS) policies
- DNetwork Access Control (NAC) policies
Show answer & explanationAnswer & explanation
Correct answer: A. URL Filtering policies
URL Filtering policies are specifically designed to control access to websites based on categories, allowing administrators to block or monitor access to specific types of content, such as gambling or adult sites.
Why the other options are wrong
- B. File Policies focus on detecting and controlling the transfer of specific file types, not website access.
- C. IPS policies focus on detecting and preventing known exploits and attack patterns, not website categories.
- D. NAC policies control network access based on device posture and user identity, not website content categories.
URL Filtering
A content security feature that categorizes websites and enforces access policies based on these categories to control user access to web content.
- Blocks or allows access to websites based on categories (e.g., gambling, social media).
- Can generate alerts or log events for policy violations.
- Often integrated into firewalls or dedicated web security gateways.
Memory trick: URL's Categorical Gatekeeper Guards Web Access.