exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 6 discussion

Actual exam question from Cisco's 300-710
Question #: 6
Topic #: 1
[All 300-710 Questions]

With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?

  • A. inline set
  • B. passive
  • C. routed
  • D. inline tap
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
14a1949
1 day, 4 hours ago
Selected Answer: D
Passive Mode: This mode is used to monitor traffic without actively participating in the traffic flow. It receives a copy of the traffic for analysis but does not alter or forward the traffic itself. Inline Tap Mode: This mode allows the device to monitor traffic inline, meaning it can see the traffic as it passes through the device, but it does not modify the traffic. It is similar to passive mode but is used in an inline deployment. Given the requirement to passively receive traffic that passes through the appliance, Inline Tap Mode (Option D) could indeed be a suitable choice as it allows the device to monitor traffic inline without altering it.
upvoted 1 times
...
Grandslam
3 months, 2 weeks ago
Selected Answer: D
With Cisco FTD software, which interface mode must be configured to >>>>passively receive traffic that >>>>passes through the appliance? INLINE TAP sends a COPY of the data to the SNORT Engineer where THAT COPY then is dropped... Meanwhile in parallel the actual traffic continues THROUGH the appliance uninterrupted. This to me fits the definition of passive receiving traffic that PASSES THROUGH the appliance. Answer D.
upvoted 2 times
...
mlu
4 months, 4 weeks ago
since the Traffic goes "THROUGH" the Firewall, Passive doesn't make sense. So "Inline tap" is correct
upvoted 1 times
...
MB2222
9 months, 3 weeks ago
It is definitely B: (passive), since the question refers to the interface mode, and not the Inline-Set "Advanced Settings".
upvoted 1 times
...
bassfunk
1 year, 5 months ago
Selected Answer: B
The answer is B. Tested it in my lab. The only interface modes are ERSPAN, Passive and None. Tap is a mode for inline pairs. Not an interface.
upvoted 2 times
Stevens0103
11 months, 2 weeks ago
Inline Pair with Tap is an interface mode。https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200908-configuring-firepower-threat-defense-int.html#:~:text=Inline%20Pair%20with%20Tap
upvoted 2 times
...
...
gc999
1 year, 6 months ago
Selected Answer: D
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200908-configuring-firepower-threat-defense-int.html#:~:text=Inline%20Pair%20with%20Tap
upvoted 1 times
...
Shortbusruss
1 year, 7 months ago
You have to really doubt the talent of anyone who answered "B" here, as Cisco is EXTREMELY clear about interface modes, which ones pass traffic THROUGH the appliance, and which ones just make copies of packets "passing by" the appliance. So much so, I have noted a couple of names in here that if my answers agree with theirs, I go back and take a HARD look at the documentation to make sure I am right. Some folks are so consistently wrong, and on such simple, basic questions, you almost gotta think they may be Cisco employees trying to muddy the waters.
upvoted 3 times
...
SegaMasterSystemAdmin
1 year, 7 months ago
Selected Answer: D
It appears to be D as the traffic does still "passes through the appliance", if it is B, then it would only receive a copy of the traffic via SPAN or ERSpan
upvoted 2 times
...
YmerG
1 year, 7 months ago
Selected Answer: D
Inline-tap for sure, because the key word here is "passing" and the interface in passive mode receives copies of the traffic
upvoted 2 times
...
Bbb78
1 year, 7 months ago
the main thing here is "passing"...with passive traffic is not "passing"
upvoted 2 times
...
saad_SEIU
1 year, 9 months ago
The answer is B, Passive Interface. The Passive interface is passively receiving traffic thought the SPAN.
upvoted 2 times
...
Joe_Blue
1 year, 10 months ago
Selected Answer: D
The correct answer is D. inline tap. In inline tap mode, the Cisco FTD appliance is configured to passively receive a copy of the traffic that is passing through it, without actively processing or inspecting the traffic. This allows for non-disruptive monitoring and analysis of network traffic.
upvoted 1 times
...
Aarow
2 years, 3 months ago
Selected Answer: D
With passive interface configuration, traffic does not "pass through" the device, the FTD is configured in an out of band mode. Inline TAP seems a better answer.
upvoted 1 times
...
dique
2 years, 5 months ago
Selected Answer: D
Answer D
upvoted 1 times
...
jaciro11
2 years, 5 months ago
Selected Answer: B
Answer here is B However most the question is formulated weirdly. Inline Set with TAP could be a better answer
upvoted 1 times
...
xziomal9
2 years, 7 months ago
Correct answer is: D
upvoted 1 times
...
eazy99
2 years, 10 months ago
Selected Answer: B
Passive is the correct answer, think about it like that. In passive mode, the FTD is (IDS) detects but can't do anything else, you are just getting a copy of the traffic On the other hand, Inline Mode is (IPS) you detect, and prevent.
upvoted 2 times
Grandslam
2 years, 10 months ago
I think Passive is incorrect because Passive sends traffic to another device and the question appears to be referencing receiving THE traffic that passes THROUGH its self. Regardless this is a horrible question. Trickery.
upvoted 2 times
Grandslam
2 years, 10 months ago
Also Passive interface is about receiving traffic from another appliance not the actual appliance the passive interface is configured on.
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago