17.2 Next-Generation Threat Defense & Secure Access Service Edge (SASE)

Key Takeaways

  • Cisco Secure Firewall (formerly Firepower NGFW / FTD) integrates Layer 3/4 stateful inspection (LINA) with Layer 7 deep packet inspection (Snort 3), Application Visibility and Control (AVC / OpenAppID), URL Filtering, and Advanced Malware Protection (AMP) under centralized management (FMC / Cisco Security Cloud Control).
  • The Snort 3 Next-Generation IPS engine introduces a multi-threaded architecture with shared memory across packet processing threads, hitless dynamic rule swaps without packet drops, hyperscan regex acceleration, and modular inspector plugins.
  • Application Visibility and Control (AVC) identifies over 4,000 applications and micro-applications regardless of port, protocol, or evasive encryption techniques, while the Encrypted Visibility Engine (EVE) identifies malicious TLS sessions without decrypting packet payloads by analyzing TLS Client Hello fingerprints and TCP dynamics.
  • Cisco Advanced Malware Protection (AMP / Cisco Secure Endpoint) and Cisco Secure Malware Analytics (Threat Grid) provide one-to-one SHA-256 disposition queries, dynamic automated cloud sandboxing, and continuous retrospective security to track and isolate Patient Zero after zero-day outbreaks.
  • Secure Access Service Edge (SASE) and Security Service Edge (SSE) converge SD-WAN Direct Internet Access (DIA) with cloud-delivered security services—including Cloud Access Security Broker (CASB), Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), DNS-layer security, and Cloud-Delivered Firewall (CD-FW)—delivered via Cisco Umbrella and Cisco Secure Access.
Last updated: August 2026

17.2 Next-Generation Threat Defense & Secure Access Service Edge (SASE)

Core Blueprint Focus: Cisco 350-401 ENCOR v1.2 topic 5.4 (describe the components of network security design: 5.4.a threat defense, 5.4.b endpoint security, 5.4.c next-generation firewall) requires candidates to design and evaluate next-generation threat defense architectures and Secure Access Service Edge (SASE) frameworks. Mastery areas include Cisco Secure Firewall / Firepower Threat Defense (FTD), the Snort 3 IPS engine, Application Visibility and Control (AVC), URL filtering, Encrypted Visibility Engine (EVE), Advanced Malware Protection (AMP / Cisco Secure Endpoint), and cloud-delivered security services (CASB, SWG, ZTNA, DNS security, and Cisco Umbrella / Cisco Secure Access).

Traditional perimeter defense models relied on static Layer 3/4 access control lists (ACLs) and stateful firewalls inspecting TCP/UDP port numbers (e.g., assuming TCP port 80 is web traffic and TCP port 22 is SSH). In modern enterprise networks—dominated by Software-as-a-Service (SaaS), hybrid cloud workloads, TLS 1.3 encryption, and remote workforces—traditional port-based controls are obsolete. Malicious command-and-control (C2) channels and data exfiltration disguise themselves within standard HTTPS (TCP 443) flows. To protect enterprise assets, security architectures must implement Layer 7 Deep Packet Inspection (DPI) at the perimeter while converging networking and security into a cloud-native Secure Access Service Edge (SASE) model.

+---------------------------------------------------------------------------------------------------+
|                         ENTERPRISE THREAT DEFENSE & SASE LANDSCAPE                                |
+---------------------------------------------------------------------------------------------------+
|                                                                                                   |
|  [ ON-PREMISES NEXT-GEN THREAT DEFENSE ]      [ CLOUD-DELIVERED SECURITY (SASE / SSE) ]           |
|  +---------------------------------------+    +-----------------------------------------------+   |
|  | Cisco Secure Firewall (FTD)           |    | Cisco Umbrella / Cisco Secure Access          |   |
|  | - L3/L4 Stateful Firewall (LINA)      |    | - DNS-Layer Security (208.67.222.222)         |   |
|  | - Snort 3 Multi-Threaded IPS Engine   |    | - Secure Web Gateway (SWG / Full Proxy)       |   |
|  | - Application Visibility (AVC)        |    | - Cloud Access Security Broker (CASB)         |   |
|  | - URL Filtering & Reputation          |    | - Zero Trust Network Access (ZTNA / Private)  |   |
|  | - Encrypted Visibility Engine (EVE)   |    | - Cloud-Delivered Firewall (CD-FW L3-L7)      |   |
|  | - Malware Defense (AMP / Threat Grid) |    | - Remote Browser Isolation (RBI)              |   |
|  +---------------------------------------+    +-----------------------------------------------+   |
|                        \                                     /                                    |
|                         \                                   /                                     |
|                          [ CATALYST SD-WAN / ENTERPRISE EDGE ]                                    |
|                          - Direct Internet Access (DIA) Local Breakout                            |
|                          - Automated IPsec/GRE Cloud OnRamp Tunnels                               |
+---------------------------------------------------------------------------------------------------+

1. Cisco Secure Firewall (FTD) Architecture & Deployment Modes

Cisco Secure Firewall runs the Firepower Threat Defense (FTD) software image, which unifies the proven Layer 2–Layer 4 stateful inspection and routing capabilities of the Cisco ASA engine (LINA) with the advanced Layer 7 inspection capabilities of the Snort IPS engine.

+---------------------------------------------------------------------------------------------------+
|                         CISCO SECURE FIREWALL (FTD) DUAL-ENGINE ARCHITECTURE                      |
+---------------------------------------------------------------------------------------------------+
|                                                                                                   |
|  INCOMING PACKET                                                                                  |
|         |                                                                                         |
|         v                                                                                         |
|  +---------------------------------------------------------------------------------------------+  |
|  | 1. LINA ENGINE (Layer 2 - Layer 4 Stateful Processing)                                      |  |
|  | - Ingress interface sanity checks, IP checksum verification.                                |  |
|  | - Layer 3 / Layer 4 Routing, NAT / PAT translation, Stateful Connection Table match.         |  |
|  | - Pre-Filter FastPath Policies (Bypasses Snort for trusted high-speed traffic).             |  |
|  +---------------------------------------------------------------------------------------------+  |
|                                                |                                                  |
|                                    DAQ (Data Acquisition Layer)                                   |
|                                                |                                                  |
|                                                v                                                  |
|  +---------------------------------------------------------------------------------------------+  |
|  | 2. SNORT 3 ENGINE (Layer 7 Deep Packet Inspection & Threat Defense)                         |  |
|  | - Protocol Decoders & Normalizers (HTTP, DNS, TLS, SMB, FTP).                                |  |
|  | - SSL/TLS Decryption & Encrypted Visibility Engine (EVE).                                   |
|  | - Application Visibility and Control (AVC / OpenAppID).                                     |
|  | - URL Filtering & Reputation Scoring (Cisco Talos Intelligence).                             |
|  | - Snort 3 IPS Rules & Vulnerability Exploit Signatures.                                     |
|  | - Cisco Advanced Malware Protection (AMP / File SHA-256 Hashing).                           |  |
|  +---------------------------------------------------------------------------------------------+  |
|                                                |                                                  |
|                                                v                                                  |
|  EGRESS FORWARDING / DROP DECISION                                                                |
+---------------------------------------------------------------------------------------------------+

FTD Management Platforms

  1. Firepower Management Center (FMC / FMCv): Centralized enterprise management appliance (hardware or virtual) capable of managing hundreds of FTD firewalls. Provides unified policy distribution, event correlation, threat reporting, automated database updates (SRU/VDB), and REST API automation.
  2. Firepower Device Manager (FDM): Lightweight, web-based on-box management tool embedded directly within FTD. Designed for single-device branch office deployments without centralized FMC infrastructure.
  3. Cisco Security Cloud Control (Cisco Defense Orchestrator / CDO): Cloud-hosted SaaS management portal providing multi-device policy consistency and orchestration across on-premises FTDs, ASAs, and cloud firewalls.

FTD Deployment Modes

+---------------------------------------------------------------------------------------------------+
|                         CISCO SECURE FIREWALL DEPLOYMENT MODES                                    |
+---------------------------------------------------------------------------------------------------+
|  Deployment Mode        | Layer Operation       | Routing & NAT       | Inspection Behavior       |
| :---------------------- | :-------------------- | :------------------ | :------------------------- |
| **Routed Mode**         | Layer 3 Default GW    | Supports OSPF, BGP,  | Inline bidirectional      |
|                         | (Different Subnets)   | EIGRP, Static, NAT  | inspection and dropping.   |
| **Transparent Mode**    | Layer 2 Bridge        | No routing/NAT; same| Inline "bump-in-the-wire" |
|                         | (Bridge Group / BVI)  | subnet on interfaces| inspection and dropping.   |
| **Inline Mode**         | Layer 2 / Layer 3     | Depends on mode      | Active inline inspection;  |
|                         | (Routed or Inline Set)|                     | drops malicious packets.   |
| **Inline Tap Mode**     | Layer 2 Inline Set    | No routing/NAT       | Copies packets to Snort;  |
|                         | (Failsafe monitoring) |                     | forwards live traffic.    |
| **Passive Mode**        | SPAN / TAP Port       | None                | Listen-only detection;    |
|                         | (Promiscuous)         |                     | generates alerts only.    |
+---------------------------------------------------------------------------------------------------+
Loading diagram...
Cisco FTD Packet Processing Pipeline and Inspection Stages

2. Snort 3 IPS Engine & Cisco Talos Intelligence

Snort 3 represents a complete architectural overhaul of the world's most widely deployed intrusion prevention system (IPS), replacing the legacy single-threaded Snort 2 architecture.

+---------------------------------------------------------------------------------------------------+
|                         SNORT 2 VS. SNORT 3 ARCHITECTURAL COMPARISON                              |
+---------------------------------------------------------------------------------------------------+
|  Architectural Feature  | Legacy Snort 2 Engine           | Modern Snort 3 Engine               |
| :---------------------- | :------------------------------ | :---------------------------------- |
| **Threading Model**     | **Single-Threaded**             | **Multi-Threaded**                  |
|                         | (Requires separate OS process   | (Single process with shared memory  |
|                         | per CPU core; high RAM usage)   | threads; minimal memory footprint)  |
| **Rule Updates**        | **Service Disruption**          | **Hitless Dynamic Rule Swaps**      |
|                         | (Drops/buffers packets during   | (Zero packet drops during rule      |
|                         | policy compilation/reload)      | compile and configuration reload)   |
| **Configuration Model** | Plain text `snort.conf`         | Structured **Lua Configuration**    |
| **Regex Matching**      | Standard PCRE                   | **Hyperscan Accelerated Regex**     |
|                         | (High CPU under heavy load)     | (High-performance multi-pattern)    |
| **Inspector Plugins**   | Hardcoded static C inspectors   | Modular C++ dynamic plugins         |
| **Rule Syntax**         | Positional single-line format   | Free-form, multi-line, payload-rule |
+---------------------------------------------------------------------------------------------------+

Cisco Talos Threat Intelligence Integration

Snort 3 is powered by Cisco Talos, the world's premier commercial threat intelligence organization:

  • Global Telemetry Grid: Analyzes over 1.5 million unique malware samples daily, 500 billion DNS queries, and millions of software vulnerability vectors.
  • Automated Real-Time Feeds: Delivers real-time Snort Rule Updates (SRU), Vulnerability Database (VDB) updates, Geolocation maps, and Security Intelligence IP/URL/Domain blacklists directly to Cisco Secure Firewall appliances.
  • Zero-Day Protection: When a new vulnerability (e.g., Log4j, Spring4Shell) is uncovered, Talos publishes active IPS exploit signatures within hours, shielding enterprise endpoints before vendor patches are deployed.

3. Application Visibility and Control (AVC), URL Filtering & EVE

Application Visibility and Control (AVC / OpenAppID)

Cisco AVC uses deep packet inspection and Cisco's open-source OpenAppID application detection engine to classify network traffic at Layer 7:

  • Over 4,000 Application Signatures: Identifies applications regardless of the port, protocol, or IP address utilized (e.g., detecting BitTorrent over TCP port 443).
  • Micro-Application Granularity: Distinguishes between sub-components within a single web application. For example, an administrator can permit Facebook Browsing while blocking Facebook File Upload and Facebook Games, or allow Microsoft 365 Outlook while rate-limiting Personal OneDrive Downloads.
  • Business Relevance & Risk Categorization: Automatically tags applications with a Risk Score (1 to 5) and Business Relevance classification (High, Medium, Low).

URL Filtering & Reputation

  • Categorizes billions of websites into 80+ categories (e.g., Gambling, Malware Sites, Phishing, Adult Content).
  • Assigns a Reputation Score from 1 (Untrusted / Malicious) to 100 (Well-Known / Trustworthy). Policies can automatically block all URLs with a reputation score below 40.

Encrypted Visibility Engine (EVE)

With the widespread adoption of TLS 1.3 and Encrypted SNI (ESNI / ECH), traditional SSL decryption becomes computationally expensive and introduces privacy/compliance challenges (e.g., HIPAA, GDPR, financial privacy).

Encrypted Visibility Engine (EVE) solves this challenge by identifying malware within encrypted TLS streams WITHOUT decrypting the payload:

  1. TLS Client Hello Fingerprinting: Inspects unencrypted handshake metadata, including supported cipher suites, TLS extensions, elliptic curve algorithms, and client version sequences.
  2. TCP Dynamics & Packet Length Analysis: Analyzes the sequence of packet lengths and inter-arrival times (SPLT - Sequence of Packet Length and Time) during the initial session handshake.
  3. Cisco Talos ML Classification: Correlates the fingerprint and packet dynamics against Cisco's cloud machine learning database to determine with >99% confidence whether the encrypted session represents legitimate enterprise traffic or a malware C2 channel.
Loading diagram...
Encrypted Visibility Engine (EVE) Malware Detection Without Decryption

4. Cisco Advanced Malware Protection (AMP) & Threat Grid Sandboxing

Cisco Secure Endpoint (formerly AMP) and Cisco Secure Malware Analytics (formerly Threat Grid) provide continuous behavioral analysis across the entire attack lifecycle.

+---------------------------------------------------------------------------------------------------+
|                         ADVANCED MALWARE PROTECTION (AMP) ARCHITECTURE                            |
+---------------------------------------------------------------------------------------------------+
|                                                                                                   |
|  [ 1. SHA-256 FILE HASHING ]                                                                      |
|   - As a file traverses the firewall, FTD computes its unique SHA-256 cryptographic hash.         |
|   - FTD queries the Cisco AMP Cloud in real time:                                                 |
|     * CLEAN: File is allowed through immediately.                                                 |
|     * MALICIOUS: File transfer is instantly dropped, and an alert is logged in FMC.               |
|     * UNKNOWN: File is allowed through (to prevent user delay), but marked for deep inspection.   |
|                                                                                                   |
|  [ 2. THREAT GRID DYNAMIC SANDBOXING ]                                                            |
|   - If a file is 'UNKNOWN', FTD uploads the binary/document to Cisco Threat Grid cloud or on-prem. |
|   - The file is detonated inside an isolated, instrumented virtual machine sandbox.               |
|   - Threat Grid observes behavior: registry modifications, DLL injections, C2 beaconing.          |
|   - Generates a Threat Score (0 to 100) and detailed behavioral indicators of compromise (IoCs).   |
|                                                                                                   |
|  [ 3. CONTINUOUS RETROSPECTIVE SECURITY ]                                                         |
|   - If an 'UNKNOWN' file detonated in Threat Grid is determined to be malicious 2 hours later,    |
|     Cisco AMP Cloud updates the global file disposition to 'MALICIOUS'.                            |
|   - AMP triggers a **Retrospective Alert** in FMC, mapping **Patient Zero** (the original host)   |
|     and displaying the complete **File Trajectory** showing every host that downloaded the file. |
+---------------------------------------------------------------------------------------------------+

5. Secure Access Service Edge (SASE) & Security Service Edge (SSE)

The SASE Convergence Model

Traditional branch office security backhauled all Internet traffic over expensive MPLS lines to a centralized corporate data center firewall (the "hub-and-spoke castle-and-moat" model). In the cloud era, this causes severe latency, bandwidth bottlenecks, and degraded SaaS performance.

Secure Access Service Edge (SASE) (defined by Gartner) converges wide-area networking (SD-WAN) with cloud-delivered security services (Security Service Edge / SSE) into a unified, globally distributed cloud edge.

+---------------------------------------------------------------------------------------------------+
|                         THE SASE ARCHITECTURAL PILLARS                                            |
+---------------------------------------------------------------------------------------------------+
|                                                                                                   |
|  +-------------------------------------+       +-----------------------------------------------+  |
|  | NETWORK AS A SERVICE (NaaS)         |       | SECURITY SERVICE EDGE (SSE / Security as SaaS)|  |
|  | [ Cisco Catalyst SD-WAN ]           |       | [ Cisco Umbrella / Cisco Secure Access ]      |
|  | - Direct Internet Access (DIA)      | <===> | - DNS-Layer Security (Port 53 Lookup Defense)  |  |
|  | - Application-Aware Routing (AAR)   |       | - Secure Web Gateway (SWG / Full Proxy)       |  |
|  | - Cloud OnRamp for SaaS / IaaS      |       | - Cloud Access Security Broker (CASB)         |  |
|  | - Automated IPsec/GRE Cloud Tunnels |       | - Zero Trust Network Access (ZTNA / Private)  |  |
|  |                                     |       | - Cloud-Delivered Firewall (CD-FW L3-L7)      |  |
|  |                                     |       | - Remote Browser Isolation (RBI)              |  |
|  +-------------------------------------+       +-----------------------------------------------+  |
|                                                |                                                  |
|                                                v                                                  |
|  +---------------------------------------------------------------------------------------------+  |
|  | UNIFIED SASE FABRIC: Cisco Secure Client (AnyConnect) + Catalyst 8000 SD-WAN Routers        |  |
|  +---------------------------------------------------------------------------------------------+  |
+---------------------------------------------------------------------------------------------------+

Core SASE / SSE Building Blocks Explained

+---------------------------------------------------------------------------------------------------+
|                         SASE / SSE COMPONENT FUNCTIONALITY MATRIX                                 |
+---------------------------------------------------------------------------------------------------+
|  SASE Component         | Primary Functional Role                   | Key Inspection Capabilities |
| :---------------------- | :---------------------------------------- | :-------------------------- |
| **DNS-Layer Security**  | Resolves DNS queries at the recursive edge| Blocks malware, C2 callbacks|
| **(Cisco Umbrella)**    | (`208.67.222.222`); blocks bad domains    | before IP connection starts.|
|                         | before TCP connection establishes.        | Extremely low latency.      |
| **Secure Web Gateway**  | Full forward cloud proxy for HTTP/HTTPS   | URL filtering, SSL decrypt, |
| **(SWG)**               | web traffic.                              | anti-virus, file inspection.|
| **Cloud Access Security**| Secures SaaS applications (M365, Box,     | API Mode (Data at rest) &   |
| **Broker (CASB)**       | Salesforce, Google Workspace).            | Inline Mode (DLP, Tenant    |
|                         |                                           | restriction, Shadow IT).   |
| **Zero Trust Network**  | Replaces broad Layer 3 VPNs with identity-| Application-specific proxy; |
| **Access (ZTNA)**       | based, least-privilege private app access.| continuous posture check    |
|                         | (Software-Defined Perimeter / SDP).       | (Cisco Duo MFA, OS hygiene).|
| **Cloud-Delivered FW**  | Stateful Layer 3–Layer 7 firewall running | IPsec/GRE tunnel inspection,|
| **(CD-FW)**             | in the cloud edge for non-web protocols.  | port/protocol enforcement.  |
| **Remote Browser**      | Air-gaps endpoint browsers by executing   | Streams safe vector pixels  |
| **Isolation (RBI)**     | risky web pages inside disposable cloud VM| to client; zero code on PC. |
+---------------------------------------------------------------------------------------------------+

CASB Modes: Out-of-Band API vs. Inline Proxy

  • API Mode (Out-of-Band): Cisco Umbrella CASB integrates directly with SaaS cloud providers (Microsoft 365, Google Drive, Box) via vendor REST APIs. It scans data at rest, classifies sensitive data (DLP), removes public sharing links from confidential files, and audits user permissions without requiring client agents.
  • Inline Proxy Mode: Intercepts real-time cloud traffic traversing the SWG. Enforces Data Loss Prevention (DLP) in real time, blocks unauthorized file uploads, and enforces Tenant Restrictions (e.g., allowing corporate @company.com Microsoft 365 logins while blocking personal @outlook.com access).

6. Configuration & Management Implementation Examples

1. Cisco IOS-XE SD-WAN / Router IPsec VTI Tunnel to Cisco Umbrella Cloud Edge

! --- Step 1: IKEv2 Configuration for Umbrella Cloud Edge ---
crypto ikev2 proposal UMBRELLA_IKEV2_PROP
 encryption aes-gcm-256
 prf sha256
 group 19 20
!
crypto ikev2 policy UMBRELLA_IKEV2_POLICY
 proposal UMBRELLA_IKEV2_PROP
!
crypto ikev2 keyring UMBRELLA_KEYRING
 peer UMBRELLA_SIG_DC1
  address 146.112.112.8               !<--- Cisco Umbrella Cloud Gateway IP
  pre-shared-key EnterpriseSecretKey2026!
!
crypto ikev2 profile UMBRELLA_IKEV2_PROFILE
 match identity remote address 146.112.112.8 255.255.255.255
 identity local email router-branch10@enterprise.org
 authentication local pre-share
 authentication remote pre-share
 keyring local UMBRELLA_KEYRING
 dpd 10 2 on-demand                   !<--- Dead Peer Detection (10s interval, 2 retries)
!
! --- Step 2: IPsec Transform Set & Crypto Profile ---
crypto ipsec transform-set TS_UMBRELLA esp-gcm 256
 mode transport
!
crypto ipsec profile UMBRELLA_IPSEC_PROFILE
 set transform-set TS_UMBRELLA
 set ikev2-profile UMBRELLA_IKEV2_PROFILE
!
! --- Step 3: Routed Virtual Tunnel Interface (VTI) to SASE Cloud ---
interface Tunnel100
 description SASE_UMBRELLA_PRIMARY_IPSEC_TUNNEL
 ip unnumbered GigabitEthernet0/0/0
 ip tcp adjust-mss 1360
 tunnel source GigabitEthernet0/0/0
 tunnel mode ipsec ipv4
 tunnel destination 146.112.112.8
 tunnel protection ipsec profile UMBRELLA_IPSEC_PROFILE

2. Cisco Firepower FTD Access Control Policy Structure (FMC Managed)

! Conceptual Rule Processing Order in Cisco Firepower Management Center (FMC):
!
! 1. PRE-FILTER POLICY:
!    - Rule 10 (FastPath): Bypass Snort for trusted SAN backup replication (TCP 3260 iSCSI).
!
! 2. SECURITY INTELLIGENCE (SI):
!    - Block known Malicious IPs, Phishing URLs, and Botnet C2 domains (Talos Feed) at Ingress.
!
! 3. ACCESS CONTROL POLICY (ACP):
!    - Rule 10: "Block_High_Risk_Apps"
!      Source: Inside_Subnets -> Dest: Any -> Apps: BitTorrent, Tor, Anonymous_Proxy -> Action: BLOCK
!
!    - Rule 20: "Inspect_Corporate_Web"
!      Source: Inside_Subnets -> Dest: Any -> Ports: HTTP/HTTPS -> Action: ALLOW
!      * SSL Decryption Policy: Enterprise_Forward_Proxy (Decrypts Outbound TLS)
!      * Inspection: Snort 3 IPS Policy (Balanced Security & Connectivity)
!      * File Policy: Block_Malware_and_Submit_ThreatGrid (AMP SHA-256 + Cloud Sandbox)
!      * AVC Filter: Permit Office365, Block OneDrive Personal Uploads
!
!    - Rule Default: "Default_Action" -> Action: BLOCK ALL TRAFFIC

3. Verification and Diagnostic CLI Commands

Firewall-FTD# system support firewall-engine-debug
Please specify an IP protocol: tcp
Please specify a client IP address: 10.1.10.50
Please specify a server IP address: 198.51.100.80
Starting trace...
10.1.10.50:52410 -> 198.51.100.80:443 6[TLS] Starting inspection on Snort 3 thread 2
10.1.10.50:52410 -> 198.51.100.80:443 6[TLS] EVE Engine: TLS Client Hello parsed, Fingerprint matched: Standard Chrome 124
10.1.10.50:52410 -> 198.51.100.80:443 6[AVC] AppID: Microsoft 365 (ID: 1420), Business Relevance: High
10.1.10.50:52410 -> 198.51.100.80:443 6[AMP] SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
10.1.10.50:52410 -> 198.51.100.80:443 6[AMP] Cloud Disposition: CLEAN (Cache TTL 3600s)
10.1.10.50:52410 -> 198.51.100.80:443 6[Verdict] Action: ALLOW (Rule: Inspect_Corporate_Web)

Router# show crypto ikev2 sa detail
Tunnel-id: 100
Local: 198.51.100.2:4500  Remote: 146.112.112.8:4500
State: READY
Encr: AES-GCM, Keysize: 256, Hash: None, PRF: SHA256, DH Group: 19
Lifetime: 86400s, Active: 4120s
DPD configured, interval: 10s, retry: 2
Test Your Knowledge

A network security architect is upgrading an enterprise firewall cluster from legacy Snort 2 to the modern Snort 3 IPS engine on Cisco Secure Firewall appliances. The operations team is concerned about packet drops and service interruptions that historically occurred during major IPS signature compilation and rule deployment windows. How does Snort 3 resolve this operational issue?

A
B
C
D
Test Your Knowledge

An enterprise security policy prohibits the decryption of outbound TLS traffic originating from the Human Resources and Executive management subnets due to strict privacy regulations. However, the security team must still detect if malware on these endpoints establishes encrypted Command and Control (C2) communications over TLS 1.3. Which Cisco Secure Firewall feature meets this requirement without performing SSL/TLS decryption?

A
B
C
D
Test Your Knowledge

An enterprise organization is migrating from a traditional data center VPN backhaul model to a cloud-native Secure Access Service Edge (SASE) architecture using Cisco Umbrella and Cisco Secure Access. The organization needs to discover unapproved cloud applications (Shadow IT), inspect data at rest in Microsoft 365 for sensitive data leaks (DLP), and enforce real-time tenant restrictions on web traffic. Which SASE component and operating mode combination provides these capabilities?

A
B
C
D
Test Your Knowledge

A user at a remote branch office downloads a zero-day executable file from the Internet. At the time of download, the file's SHA-256 hash was unknown to Cisco Advanced Malware Protection (AMP Cloud), and the file was allowed to execute. Three hours later, Cisco Threat Grid (Secure Malware Analytics) finishes detonating the file in a cloud sandbox and identifies it as ransomware. How does Cisco AMP remediate this security threat across the enterprise?

A
B
C
D