exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 35 discussion

Actual exam question from Cisco's 300-710
Question #: 35
Topic #: 1
[All 300-710 Questions]

When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance. Which deployment mode meets the needs of the organization?

  • A. inline tap monitor-only mode
  • B. passive monitor-only mode
  • C. passive tap monitor-only mode
  • D. inline mode
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
14a1949
1 day, 3 hours ago
Selected Answer: A
Option B, passive monitor-only mode, is also a valid approach for evaluating traffic without affecting the network. In this mode, the device monitors traffic passively, meaning it doesn't interfere with the traffic flow, which meets the requirement of not affecting the network. However, the key difference is that inline tap monitor-only mode (option A) provides visibility into what the ASA FirePOWER module would have done to the traffic if it were actively managing it, without actually impacting the network. This can be particularly useful for evaluating the potential impact of security policies and actions.
upvoted 1 times
...
tinyJoe
1 week ago
Selected Answer: B
I agree that the answer is B. "However, in this mode, the ASA does apply its policies to the traffic, so traffic can be dropped due to access rules, TCP normalization, and so forth." https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/configuration/firewall/asa-910-firewall-config/access-sfr.html#:~:text=the%20ASA%20does%20apply%20its%20policies%20to%20the%20traffic
upvoted 1 times
tinyJoe
1 week ago
However, it depends on what is meant by the description “You must operate the ASA in single context transparent mode. If “single context” means the same thing as “not multi instance”, then the answer would be A.
upvoted 1 times
...
...
14a1949
1 week, 1 day ago
Selected Answer: B
I can understand why you might think that, but let's clarify the best option. To evaluate the contents of the traffic without affecting the network, the correct deployment mode would be: **B. passive monitor-only mode** In passive monitor-only mode, the Cisco ASA Firepower module can analyze traffic without actively interfering with it, making it ideal for evaluating traffic without impacting the network. **A. inline tap monitor-only mode** would still involve placing the device inline, which can affect network traffic flow to some extent.
upvoted 1 times
...
spambox730
6 months ago
Selected Answer: A
Passive monitor only (B) could be the answer if there was only 1 instance but the question says there are more tan one. Thus the second option which does not affect traffic is inline tap monitor only (A)
upvoted 1 times
...
bobie
7 months, 2 weeks ago
Selected Answer: A
Inline tap monitor-only mode (ASA inline)—In an inline tap monitor-only deployment, a copy of the traffic is sent to the ASA FirePOWER module, but it is not returned to the ASA. Inline tap mode lets you see what the ASA FirePOWER module would have done to traffic, and lets you evaluate the content of the traffic, without impacting the network. However, in this mode, the ASA does apply its policies to the traffic, so traffic can be dropped due to access rules, TCP normalization, and so forth.
upvoted 1 times
...
ureis
8 months, 3 weeks ago
A. inline tap monitor-only mode - Affect CPU and hardware intensive B. passive monitor-only mode - Only monitor the traffic - Correct option C. passive tap monitor-only mode - Not exist D. inline mode - Question not asking to copy all the traffic, so not a option here
upvoted 3 times
...
Joe_Blue
10 months, 1 week ago
Selected Answer: C
The Firepower module can be deployed in either inline mode, passive monitor-only mode, or passive tap monitor-only mode. In this mode, the Cisco ASA Firepower module is configured to passively monitor traffic without introducing any delay or disruption to the network. This is achieved by configuring the module to operate in tap mode, where a copy of the traffic is sent to the module for inspection and analysis, but the original traffic continues to flow uninterrupted.
upvoted 1 times
...
bassfunk
1 year, 2 months ago
Selected Answer: A
A is correct as inline would drop packets and therefor, affect the network.
upvoted 1 times
...
dique
1 year, 4 months ago
Selected Answer: A
Correct answer is: A
upvoted 1 times
...
xziomal9
1 year, 7 months ago
Selected Answer: A
Correct answer is: a
upvoted 1 times
...
harshal0408
1 year, 8 months ago
A is correct
upvoted 1 times
...
Grandslam
1 year, 9 months ago
Selected Answer: A
A @Orotta is correct
upvoted 1 times
...
trickbot
1 year, 10 months ago
Thank you @orotta for the reference, and reminder that we are talking about an ASA with firepower module. The answer is A inline TAP
upvoted 1 times
...
orotta
1 year, 11 months ago
" Let you evaluate the content of the traffic, without impacting the network. " The question is taken exact sentence from the Cisco site for the Inline tap monitor-only Mode. Please see link below. So A is the correct answer. https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/configuration/firewall/asa-910-firewall-config/access-sfr.html
upvoted 4 times
TLOVE
1 year, 8 months ago
Orotta, thanks for the link, it confirms the answer is (A) Inline Tap mode
upvoted 1 times
...
...
jamesque23
2 years, 1 month ago
A The problem with B is that in passive monitor-only you cannot have more than one instance. Passive monitor-only (traffic forwarding) mode—If you want to prevent any possibility of the ASA with FirePOWER Services device impacting traffic, you can configure a traffic-forwarding interface and connect it to a SPAN port on a switch. In this mode, traffic is sent directly to the ASA FirePOWER module without ASA processing. The traffic is dropped, and nothing is returned from the module, nor does the ASA send the traffic out any interface. You must operate the ASA in single context transparent mode to configure traffic forwarding. https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/configuration/firewall/asa-910-firewall-config/access-sfr.html
upvoted 2 times
kj2022
1 year, 8 months ago
A is right answer
upvoted 1 times
...
...
elliot67
2 years, 2 months ago
The tap mode "IS affecting the traffic", so B is correct
upvoted 2 times
...
Bobster02
2 years, 7 months ago
Indeed, A fits better. Inline tap monitor-only mode (ASA inline)—In an inline tap monitor-only deployment, a copy of the traffic is sent to the ASA FirePOWER module, but it is not returned to the ASA. Inline tap mode lets you see what the ASA FirePOWER module would have done to traffic, and lets you evaluate the content of the traffic, without impacting the network. However, in this mode, the ASA does apply its policies to the traffic, so traffic can be dropped due to access rules, TCP normalization, and so forth.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago