exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 5 discussion

Actual exam question from Cisco's 300-710
Question #: 5
Topic #: 1
[All 300-710 Questions]

What is the difference between inline and inline tap on Cisco Firepower?

  • A. Inline tap mode can send a copy of the traffic to another device.
  • B. Inline tap mode does full packet capture.
  • C. Inline mode cannot do SSL decryption.
  • D. Inline mode can drop malicious traffic.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
14a1949
1 week, 2 days ago
Selected Answer: D
D. Inline mode can drop malicious traffic. In inline mode, the device is placed directly in the path of network traffic and can actively block or drop malicious traffic. In contrast, inline tap mode sends a copy of the traffic to another device for analysis without affecting the actual traffic flow.
upvoted 1 times
...
gwb
5 months, 1 week ago
D This is a good reference site for different deployment mode https://networkinterview.com/cisco-ftd-deployment-modes/
upvoted 2 times
...
Cokamaniako
1 year, 2 months ago
Selected Answer: D
Answer D Inline mode can drop traffic Inline Tap only can monitoring traffic
upvoted 1 times
...
jaciro11
1 year, 11 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
aaInman
2 years ago
Selected Answer: D
The correct answer is D Directly from the Official Cisco Press Cert Guide: "A threat defense in inline interface mode can block unintended traffic while it remains invisible to the network hosts. Inline mode allows a threat defense to block traffic based on the access control and intrusion rules you enable."
upvoted 1 times
...
xziomal9
2 years ago
Selected Answer: D
Correct answer is: D
upvoted 1 times
...
Grandslam
2 years, 4 months ago
Selected Answer: D
INLINE TAP Copies the data to the SNORT Engine to be checked but then dropped while the actual data flow continues uninterrupted. Therefore, INLINE TAP does not send traffic to another device. The Data is copied but not captured. You still would need to enable packet capture to capture packets (AKA Save PCAP). INLINE: Both inline and Inline Tap mode do not support SSL Decryption-resign... Although im a bit conflicted by this.... Truth is that Inline Mode can DROP malicious traffic but remember that Inline TAP mode CANNOT. Agan this is because tap mode sends a copy of the data to be inspected but not the actual data. Best Answer is D.
upvoted 2 times
...
aadach
2 years, 8 months ago
oh sorry, ONLY D !
upvoted 3 times
...
aadach
2 years, 8 months ago
A 1. With inline tap mode, the NGFW is only working with a copy of your data path traffic, as opposed to being inline with the actual data path. 2. It still sees all your traffic and can detect suspect traffic, but it cannot block your actual data path. 3. This lets you learn about how the NGFW responds in your particular environment, perhaps building your knowledge and confidence in preparation for Inline mode. 4. False positives and hardware failures will not affect your network connectivity. 5. However, there is a risk of some malicious traffic making inside your protected network.
upvoted 2 times
...
Sarbi
2 years, 9 months ago
sorry the correct answer is D only
upvoted 1 times
...
Sarbi
2 years, 9 months ago
The correct answer is B
upvoted 1 times
Grandslam
2 years, 4 months ago
TAP does not packet capture. It simply duplicates traffic to a provided destination.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago