exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 29 discussion

Actual exam question from Cisco's 300-710
Question #: 29
Topic #: 1
[All 300-710 Questions]

With Cisco FTD software, which interface mode must be configured to passively receive traffic that passes through the appliance?

  • A. ERSPAN
  • B. firewall
  • C. tap
  • D. IPS-only
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trickbot
Highly Voted 2 years, 11 months ago
Selected Answer: D
We're screwed with this question. The correct answer depends on whether the question is based on the FMC configuration Guide, or the FMC GUI user interface. If this question comes from the FMC configuration Guide, the answer could very well be D - IPS-only mode. According to the first sentence of the "INTERFACE MODES AND TYPES" section of The FMC configuration manual: "You can deploy FTD interfaces in two modes: Regular firewall mode and IPS-only mode." TAP mode would be an Advanced setting on an interface in IPS-only mode. If this question is based on the FMC GUI, then there are three modes available. Two mode choices on Firewall mode interfaces. Default is mode:none, but mode can be set to passive mode, or ERSPAN mode. There is one mode on an inline pair interface, "Tap mode" found in the advanced options. And to muddy the waters even more, ERSPAN could also be the correct answer because ERSPAN traffic is passive copies of traffic that doesnt go through the device, but the original traffic still has to go out somewhere, and that somewhere is probably through that ftd's firewall mode interfaces. I'm undecided between IPS-only mode, and TAP mode.
upvoted 6 times
...
SegaMasterSystemAdmin
Highly Voted 1 year, 7 months ago
Selected Answer: C
IDS is passive but IPS is not, with IPS the inline traffic can be dropped. I go with tap
upvoted 6 times
...
14a1949
Most Recent 1 week, 2 days ago
Selected Answer: D
For Cisco FTD software, the correct interface mode to passively receive traffic is IPS-only mode (option D). This mode allows the appliance to monitor and analyze traffic without actively participating in the traffic flow. Tap mode (option C) is another passive monitoring option, but it is typically used in inline deployments where the device is physically inserted into the network path. In contrast, IPS-only mode is specifically designed for passive monitoring without affecting the traffic flow.
upvoted 1 times
...
xBojmir215x
3 weeks ago
Selected Answer: D
It's gotta be D, IPS-only. Of the interface modes, there's Routed, Passive and ERSPAN. Tap is a mode that's used with inline tap or inline set. IPS-only is NOT an interface mode, however it can be configured to allow traffic to flow through an interface passively, as counterintuitive as that might seem.
upvoted 1 times
...
Doris8000
5 months, 2 weeks ago
Agree it should be D as the TAP woulnd't let the traffic pass
upvoted 1 times
...
gwb
11 months, 1 week ago
I don't understand why Cisco exam is doing this tricky question. Although I don't like this kind of question, I think I am going to choose IPS-Only mode. like trickbot explained very well below. I am more focusing higher interface mode (firewall vs IPS-mode) although TAP and ERSPAN are also possible answers.
upvoted 1 times
...
achille5
1 year, 5 months ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/fpmc-config-guide-v622_chapter_01111001.html
upvoted 2 times
achille5
8 months ago
https://rayka-co.com/lesson/cisco-firepower-deployment-modes/
upvoted 1 times
...
...
bassfunk
1 year, 5 months ago
Selected Answer: A
I wish there was a way to upload pics to these boards. I'm looking at the FMC right now and the only interface modes are passive, ERSPAN or none. I'm going with ERSPAN. Some of you might be going off of old guides based on older versions of the software. I'm using FMC7.2.
upvoted 4 times
...
killian64
1 year, 5 months ago
A - ERSPAN. If we're talking interface type, ERSPAN is the only option here. tap is a setting on on inline set (which isn't an interface type).
upvoted 2 times
...
Marco_Vela03
1 year, 8 months ago
D is correct, IPS-Only is an interface mode. Tap mode is a type of interface mode can be deployed: IPS-only interfaces can be deployed as the following types
upvoted 1 times
...
saad_SEIU
1 year, 9 months ago
Selected Answer: A
I would go with ERSPAN, this is a Passive interface with encapsulating mode. TAP is a copy of the traffic.
upvoted 3 times
...
Joe_Blue
1 year, 10 months ago
Selected Answer: C
The correct answer is C, tap. The tap mode is used for passive monitoring of traffic without affecting the traffic flow. The traffic is simply copied to the tap interface for analysis, while the original traffic continues to its destination.
upvoted 3 times
...
Weyland
2 years, 3 months ago
Selected Answer: D
From the start, only two answers are possible. B and D. There are only two interface modes on FTD, "You can deploy FTD interfaces in two modes: Regular firewall mode and IPS-only mode. You can include both firewall and IPS-only interfaces on the same device. IPS-only interfaces can be deployed as the following types: Inline Set, with optional Tap mode". So you could have IPS-only as inline with tap that would make it into IDS and therefore passive. Firewall interface mode can be deployed as Routed or Bridge Groups with BVI. Do your own reading here: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/interface_overview_for_firepower_threat_defense.html
upvoted 3 times
Weyland
2 years, 3 months ago
And you could also set an IPS-only interface to passive to boot.
upvoted 1 times
...
Joninjimbo
1 year, 2 months ago
Agree with D according to the Cisco docs. IPS-only mode selected means you can use inline tap which satisfies the question criteria. Updated link for version 7.0 here which still holds true: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/interface_overview_for_firepower_threat_defense.html
upvoted 1 times
...
...
BorZol
2 years, 4 months ago
TAP interface is not copy any traffic to other interface. Just received it. (Passive) IPS-only the correct. —An inline set acts like a bump on the wire, and binds two interfaces together to slot into an existing network. This function allows the system to be installed in any network environment without the configuration of adjacent network devices. Inline interfaces receive all traffic unconditionally, but all traffic received on these interfaces is retransmitted out of an inline set unless explicitly dropped.
upvoted 1 times
ureis
1 year, 8 months ago
A TAP is a network device that copies and transfers traffic to another system. Unlike a SPAN port on a switch, which is configured at the software level, a network TAP is dedicated hardware that is designed to replicate and transfer traffic.
upvoted 1 times
...
...
dique
2 years, 4 months ago
Selected Answer: C
Correct answer: C
upvoted 3 times
...
johanhc20
2 years, 5 months ago
Selected Answer: C
Correct C With tap mode, the FTD is deployed inline, but the network traffic flow is undisturbed. Instead, the FTD makes a copy of each packet so that it can analyze the packets. Note that rules of these types do generate intrusion events when they are triggered, and the table view of intrusion events indicates that the triggering packets would have dropped in an inline deployment. There are benefits to using tap mode with FTDs that are deployed inline
upvoted 3 times
...
Soter
2 years, 6 months ago
of the "Interface modes" the only valid answers is "TAP" or "ERSPAN" Tap is passive and traffic is not going through the FTD, but with ERSPAN it does. Further there is no "IPS-only" mode on interface. if any discussion about "xxx-only" mode is shout be "IDS-only" mode and that would be a passive interface mode
upvoted 1 times
Grandslam
2 years, 6 months ago
With Cisco FTD software, ****which interface mode**** must be configured to passively receive traffic that passes through the appliance? You can deploy FTD interfaces in two modes: Regular firewall mode and IPS-only mode. D
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago