Which two considerations must be made when deleting and re-adding devices while managing them via Cisco FMC? (Choose two.)
A.
An option to re-apply NAT and VPN policies during registration is available, so users do not need to re-apply the policies after registration is completed.
B.
Before re-adding the device in Cisco FMC, the manager must be added back.
C.
Once a device has been deleted, it must be reconfigured before it is re-added to the Cisco FMC.
D.
The Cisco FMC web interface prompts users to re-apply access control policies.
E.
There is no option to re-apply NAT and VPN policies during registration available, so users need to re-apply the policies after registration is completed.
When a device is deleted and then re-added, the FMC web interface prompts you to re-apply your access control policies. However, there is no option to re-apply the NAT and VPN policies during registration. Any previously applied NAT or VPN configuration will be removed during registration and must be re-applied after registration is complete.
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/device_management_basics.html
***copied from cisco configuration guide***
When a device is deleted and then re-added, the FMC web interface prompts you to re-apply your access control policies. However, there is no option to re-apply the NAT and VPN policies during registration. Any previously applied NAT or VPN configuration will be removed during registration and must be re-applied after registration is complete.
https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/device_management_basics.html
It's D & E for sure.
"When a device is deleted and then re-added, the FMC web interface prompts you to re-apply your access control policies. However, there is no option to re-apply the NAT and VPN policies during registration. Any previously applied NAT or VPN configuration will be removed during registration and must be re-applied after registration is complete."
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Device_Management_Basics.html#ID-2242-00000786
When a device is deleted from FMC, the manager is not automatically removed.
D and E are correct.
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Device_Management_Basics.html#ID-2242-00000786:~:text=When%20a%20device,registration%20is%20complete.
option B is also correct - the FTD needs to have the manager added after the FTD is deleted from the FMC(trust me it happened to me) ....but this question is more for FMC - so I would go with DE
D&E is correct
https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/device_management_basics.html?bookSearch=true
When a device is deleted and then re-added, the FMC web interface prompts you to re-apply your access control policies. However, there is no option to re-apply the NAT and VPN policies during registration. Any previously applied NAT or VPN configuration will be removed during registration and must be re-applied after registration is complete.
E is definitely correct, though I think B is a better answer than C. When registering the device, it does have a box to select the ACP to apply, but it automatically deploys the configuration. When you delete a device from the FMC, you need to go to the FTD's CLI and add the manager before adding the device to the FMC.
You don't have to add the manager back to the device *before* you add it in the FMC. I can add the device back in the FMC a year in advance if I want, it will simply sit there and wait for the device to reach out for registration. It's kind of a trick question.
You're over analyzing. You cannot add a device to the FMC without a manager configured on the device. You will get a timeout error after a few minutes.
D+E is correct:
"When a device is deleted and then re-added, the Firepower Management Center web interface prompts you to re-apply your access control policies. However, there is no option to re-apply the NAT and VPN policies during registration. Any previously applied NAT or VPN configuration will be removed during registration and must be re-applied after registration is complete. "
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
14a1949
1 day, 8 hours agoSamer0100
3 months, 3 weeks agofreemen810
5 months, 2 weeks agoStevens0103
5 months, 4 weeks agobassfunk
10 months, 3 weeks agogc999
1 year agoBbb78
1 year, 2 months agoTHEODORABLE
1 year, 2 months agorcharger00
2 years, 1 month agoSanchezEldorado
2 years, 2 months agotrudint
1 year, 1 month agobassfunk
10 months, 3 weeks agoiulianm
1 year, 9 months agonetwguy
2 years, 10 months ago