Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network engineer is configuring a Cisco Firepower Threat Defense (FTD) device to protect internal web servers. The security policy requires that all incoming traffic to the web servers on port 443 must be inspected for malicious content, but only after the SSL/TLS session has been successfully decrypted. Which FTD policy type is specifically used to manage the decryption and re-encryption of SSL/TLS traffic for inspection?

  1. ASSL Policy
  2. BFile Policy
  3. CAccess Control Policy
  4. DIntrusion Policy
Show answer & explanation

Correct answer: A. SSL Policy

The SSL Policy in Cisco FTD is specifically designed to control the decryption and re-encryption of SSL/TLS encrypted traffic. It allows the FTD to act as a man-in-the-middle to inspect the unencrypted content for threats before re-encrypting and forwarding it.

Why the other options are wrong

  • B. File Policy defines how to inspect files for malware or specific content, but it also requires decryption first for encrypted files.
  • C. Access Control Policy defines which traffic is allowed or denied based on layers 3-4 criteria, but it doesn't handle SSL decryption.
  • D. Intrusion Policy defines how to inspect traffic for intrusion attempts, but it requires the traffic to be decrypted first by the SSL Policy for effective inspection.

Cisco FTD SSL Policy

A dedicated policy within Cisco Firepower Threat Defense (FTD) that defines rules for handling SSL/TLS encrypted traffic, including whether to decrypt it for inspection, block it, or allow it to pass through without decryption.

  • Enables deep packet inspection of encrypted traffic.
  • Requires the FTD to act as a proxy (man-in-the-middle).
  • Can apply different decryption actions based on source, destination, and certificates.

Memory trick: SSL Policy: Unlock the 'S' for Inspection!

More Security questions