Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: A network administrator is configuring Cisco…

A network administrator is configuring Cisco Firepower Threat Defense (FTD) in routed mode to provide intrusion prevention (IPS) for internal traffic. They create an access control rule that allows traffic from the internal network (10.0.0.0/8) to the internet, and they attach an intrusion policy to this rule. After deploying the configuration, they generate known malicious traffic from a test host and observe that no alerts are triggered in the Firepower Management Center (FMC). The administrator checks the FTD and confirms that the Snort process is running, and the rule is at the top of the access control policy with action 'Allow'. What is the most likely cause of this issue?

⚠ Common exam trap

Cisco often tests the distinction between 'Allow' and 'Allow with Intrusion Prevention' as a common pitfall, where candidates assume attaching an intrusion policy to any rule automatically invokes Snort inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The access control rule action is set to 'Allow' rather than 'Allow with Intrusion Prevention'.

In Cisco Firepower Threat Defense (FTD), an access control rule with action 'Allow' permits traffic without sending it to the Snort intrusion inspection engine. To enable IPS, the rule action must be 'Allow with Intrusion Prevention', which explicitly invokes the intrusion policy. Since the rule was set to 'Allow', the malicious traffic bypassed Snort inspection entirely, so no alerts were generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The FTD is configured in transparent mode.

    Why it's wrong here

    The scenario states it is in routed mode.

  • The traffic is being fast-pathed and bypassing the Snort engine.

    Why it's wrong here

    Fast-pathing is disabled by default when intrusion policy is attached to a rule with proper action.

  • The access control rule action is set to 'Allow' rather than 'Allow with Intrusion Prevention'.

    Why this is correct

    IPS inspection requires the rule action to explicitly include intrusion prevention.

  • The intrusion policy is not associated with the correct preprocessor.

    Why it's wrong here

    Preprocessors are automatically configured based on the intrusion policy.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.