Answer: C
Reason: the command "capture-traffic" is used for SNORT Engine Captures. To capture a LINA Engine Capture, you use the "capture" command. Since the Lina Engine represents the actual physical interface of the device, "capture" is the only reasonable choice
Reference: https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html#anc10
The specific command to capture all traffic on an interface:
capture <capture-name> interface <interface-name>
I reluctantly choose D because the interface option is not given.
The correct command to capture all packets that hit an interface on the Cisco FTD CLI is:
**D. capture WORD**
This command allows you to specify the interface and capture parameters, making it versatile for different capture needs[1](https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html)[2](https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html).
The correct command to capture all packets that hit an interface on the Cisco FTD CLI is:
**D. capture WORD**
This command allows you to specify the interface and capture parameters, making it versatile for different capture needs[1](https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/ac_1.html)[2](https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html).
You all think too hard
To capture traffic from the Firewall Engine, you use the capture command.
The capture-traffic command captures the traffic from the Firepower engine.
Im going with D on this one. You cannot send the command "capture" from CLI - the command needs a name argument following "capture". You can send the command "capture [WORD]" with following <cr> , from both LINA and CLIish.
James is right about the capture-traffic command, but D is a better answer than C. Go into the cli, type "capture" then hit the question mark. The only option is "WORD". WORD represents a capture name. D is more specific than C.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
James3222
Highly Voted 2 years, 12 months agoTHEODORABLE
10 months, 3 weeks agoGrandslam
Highly Voted 1 year, 7 months agod0980cc
Most Recent 3 weeks, 3 days ago14a1949
2 months, 2 weeks ago14a1949
2 months, 2 weeks agoLangaMos
8 months, 3 weeks agoTHEODORABLE
10 months, 3 weeks agoCokamaniako
11 months agoTHEODORABLE
11 months agoTHEODORABLE
10 months, 3 weeks agoJoe_Blue
1 year agoWeyland
1 year, 4 months agoEstebandido2022
1 year, 5 months agojohanhc20
1 year, 8 months agoxziomal9
1 year, 9 months agoxYanivDx
1 year, 10 months agoharshal0408
1 year, 11 months agoSanchezEldorado
1 year, 11 months ago