You deployed Cloud NGFW Enterprise endpoints and must inspect VM traffic with the IPS feature. What should you configure to apply IPS inspection to VM traffic?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a firewall rule matching the VMs' source/destination IP addresses and use the apply_security_profile_group action..
Why this is the answer
To apply Intrusion Prevention System (IPS) inspection to VM traffic using Cloud NGFW Enterprise, you need to create a firewall policy rule that specifically targets that traffic. This rule must identify the relevant VMs by their source or destination IP addresses. The key action to enable IPS inspection is applysecurityprofilegroup, which links the traffic to a predefined security profile group containing IPS configurations. Incorrect options: Packet Mirroring is used for capturing and analyzing network traffic, not for applying inline security features like IPS. Using gotonext in a firewall rule directs traffic to the next rule in the policy, it does not apply security profiles. Firewall rules do not match on VM hostnames; they operate on network-level attributes like IP addresses, ports, and protocols.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed