SNCF — Securing Networks with Firepower — Question 161

A company is in the process of deploying intrusion prevention with Cisco FTDs managed by a Cisco FMC. An engineer must configure policies to detect potential intrusions but not block the suspicious traffic. Which action accomplishes this task?

Answer options

Correct answer: B

Explanation

The correct answer is B because configuring IPS mode and unchecking the 'Drop when inline' option allows the system to detect intrusions without blocking traffic. The other options either enable blocking or use IDS mode, which is not suitable for intrusion prevention without blocking.