Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard

A company is using Cisco Firepower Threat Defense (FTD) deployed in transparent mode. A network engineer needs to configure a security policy that allows specific internal servers to initiate connections to external web servers on port 443, but blocks all other internal-to-external traffic. Additionally, the policy must inspect the encrypted HTTPS traffic for malware. Which Firepower feature enables deep inspection of encrypted traffic for threats?

  1. AIntrusion Policy
  2. BSSL Policy
  3. CAccess Control Policy
  4. DFile Policy
Show answer & explanation

Correct answer: B. SSL Policy

To inspect encrypted HTTPS traffic for malware and other threats, a Cisco Firepower Threat Defense (FTD) deployment requires an SSL Policy. The SSL Policy dictates whether encrypted traffic should be decrypted, what criteria trigger decryption, and how the decrypted traffic is then handled by other inspection policies (e.g., Intrusion, File).

Why the other options are wrong

  • A. An Intrusion Policy detects and prevents known threats and exploits, but it typically acts on unencrypted or already decrypted traffic.
  • C. An Access Control Policy defines what traffic is permitted or denied, but it does not perform deep inspection of encrypted content itself; it relies on other policies for that.
  • D. A File Policy detects and blocks specific file types or malware within files, but it also requires the traffic to be decrypted first if it's encrypted.

Cisco FTD SSL Policy

A security policy in Cisco Firepower Threat Defense (FTD) that controls the decryption and re-encryption of encrypted (SSL/TLS) traffic for deep inspection by other security policies.

  • Determines which encrypted traffic should be decrypted based on source, destination, port, etc.
  • Uses either a trusted CA certificate (for re-signing) or an untrusted CA certificate (for blocking).
  • Essential for inspecting HTTPS and other SSL/TLS protected applications for threats and malware.
  • Works in conjunction with Access Control, Intrusion, and File policies.

Memory trick: FTD Inspects Traffic: ACL, SSL, Intrusion, File

More Security questions