Cisco CCNP Security Core (SCOR) 350-701Content SecurityHard

A security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to apply different security policies based on user identity, rather than just IP address. This requires integration with the organization's Active Directory. Which Firepower Management Center (FMC) feature must be configured to achieve this identity-based content security enforcement?

  1. ANetwork Discovery Policy
  2. BRealm Configuration
  3. CIdentity Policy
  4. DSecurity Group Tags (SGTs)
Show answer & explanation

Correct answer: C. Identity Policy

The Identity Policy in Firepower Management Center (FMC) is specifically used to integrate with external identity sources like Active Directory. It maps users and user groups to security policies, enabling identity-based access control and content security enforcement on the FTD.

Why the other options are wrong

  • A. A Network Discovery Policy is used to discover hosts, applications, and vulnerabilities on the network; it does not directly configure identity-based access control.
  • B. Realm Configuration is a part of setting up identity sources within the Identity Policy, but the overarching feature that enables identity-based enforcement is the Identity Policy itself.
  • D. Security Group Tags (SGTs) are used for Cisco TrustSec segmentation and policy enforcement, but the primary mechanism for integrating AD and mapping users to policies in FTD/FMC is the Identity Policy.

FMC Identity Policy

A Firepower Management Center (FMC) policy that integrates with external identity sources (e.g., Active Directory) to enable identity-based access control and content security.

  • Maps users/groups to security policies.
  • Enables granular, user-aware firewall rules.
  • Requires integration with an identity source (e.g., AD, LDAP).

Memory trick: Identity Policy: Your digital ID card for network access.

More Content Security questions