Which Signature Sets Are Available in vManage for IPS?
Which signature sets are available in vManage under the security policy configuration for IPS?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether you know the exact IPS signature-set names offered by vManage; the trap is confusing IPS signature sets with malware or blacklist categories that belong to other Cisco SD-WAN security features.
vManage's security policy IPS configuration exposes exactly three predefined signature sets: Connectivity, Balanced, and Security. This page confirms option A is the correct answer and explains why combinations containing Malware or Blacklist are invalid.
Many learners choose C (Malware, Security, Connectivity) because 'Malware' sounds like an IPS profile, but malware protection is a separate Cisco SD-WAN security feature, not one of vManage's IPS signature sets.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cisco SD-WAN vManage presents three selectable IPS signature sets under the security policy configuration: Connectivity, Balanced, and Security. Option A lists exactly this triad, which matches the vManage GUI and the Cisco intrusion-prevention documentation. No other option reproduces this exact combination. The signature sets tune the Snort/IPS signature profile for different traffic profiles, with Connectivity favoring performance, Balanced as the middle ground, and Security applying the most aggressive inspection. Because the question asks which sets are available, only the set that contains all three correct names and no extraneous entries qualifies.Why the Other Options Are Wrong
Option B mixes Malware and Blacklist with Connectivity; neither Malware nor Blacklist is an IPS signature set in the vManage security policy workflow. Option C likewise includes Malware, which is handled elsewhere, and leaves out Balanced entirely. Option D replaces the real Connectivity set with Blacklist, so it fails on two counts: Blacklist is not an IPS signature set, and the mandatory Connectivity set is missing. The only distractor names that could tempt a test-taker are Malware and Blacklist, both of which appear in other areas of Cisco SD-WAN security configuration rather than in the IPS signature-set selector.Community Comment Notes
Every voter in the thread selected A, and the comments reinforce that unanimity. Loi2525 wrote, "Indeed A, see NetworkChamps' link." Networkchamp87 supplied the Cisco intrusion-prevention guide for verification, which documents the three signature sets. Gycu simply stated "A correct answer," and Stanleymahamadi agreed with "A correct after review." No commenter proposed Malware or Blacklist as an IPS signature set, so the community consensus aligns with the official Cisco documentation and with the answer established here.Official Reference
Exam Strategy
Memorize the vManage IPS signature-set triad as Connectivity, Balanced, and Security. If an answer option introduces Malware or Blacklist for an IPS signature-set question, eliminate it immediately without further analysis.
Frequently Asked Questions
Why is Malware not one of the vManage IPS signature sets?
Malware protection is handled by separate Cisco SD-WAN security features, while the IPS signature sets selectable in vManage security policy are only Connectivity, Balanced, and Security.
Does the Balanced signature set appear in vManage IPS configuration?
Yes. Balanced is one of the three predefined IPS signature sets in vManage, along with Connectivity for higher throughput and Security for stricter inspection.
Related Analysis
Practice All 300-415 Questions
Access 120 questions with complete answers and detailed explanations.
View Full 300-415 Practice Test →