PrepAway - Latest Free Exam Questions & Answers

Which three statements about protocol inspection on the Cisco ASA adaptive security appliance are true?

Which three statements about protocol inspection on the Cisco ASA adaptive security appliance are true? (Choose three. )

PrepAway - Latest Free Exam Questions & Answers

A.
All inspections are enabled by default.

B.
If you want to enable inspection globally for a protocol that is not inspected by default or if you want to globally disable inspection for a protocol, you can edit the default global policy.

C.
If you want to enable inspection globally for a protocol that is not inspected by default or if you want to globally disable inspection for a protocol, you must edit the default global policy; you cannot disable the default global policy and apply a new global policy.

D.
For the security appliance to inspect packets for signs of malicious application misuse, you must enable advanced (application layer) protocol inspection.

E.
The protocol inspection feature of the security appliance securely opens and closes negotiated ports and IP addresses for legitimate client-server connections through the security appliance

F.
If inspection for a protocol is not enabled, traffic for that protocol may be blocked.


Leave a Reply