Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy

A network security engineer is configuring a Cisco Firepower Threat Defense (FTD) device to inspect traffic for known vulnerabilities. Which security intelligence feed should be configured to block access to IP addresses and URLs that are associated with active botnet command and control servers?

  1. ACisco Talos Vulnerability Intelligence
  2. BCisco Talos Reputation Intelligence
  3. CCisco Talos Indicators of Compromise (IOC)
  4. DCisco Talos Malware Intelligence
Show answer & explanation

Correct answer: B. Cisco Talos Reputation Intelligence

Cisco Talos Reputation Intelligence provides real-time updates on malicious IP addresses and URLs, including those used by botnet command and control servers, making it the most suitable feed for blocking such threats.

Why the other options are wrong

  • A. Vulnerability Intelligence focuses on known software flaws, not active malicious IP addresses or URLs.
  • C. IOCs are broader and can include many types of indicators, but Reputation Intelligence is more direct for blocking known malicious IPs/URLs.
  • D. Malware Intelligence focuses on file hashes and characteristics of malware, not directly on C2 IP/URL blocking.

Cisco Talos Reputation Intelligence

A security intelligence feed from Cisco Talos that provides real-time reputation scores for IP addresses and URLs, identifying and blocking known malicious sources.

  • Focuses on IP addresses and URLs.
  • Identifies botnet C2s, phishing sites, and other malicious infrastructure.
  • Used for proactive blocking of known bad actors.

Memory trick: Talos feeds help you prevent the bad guys from getting through.

More Visibility and Enforcement questions