exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 160 discussion

Actual exam question from Cisco's 300-710
Question #: 160
Topic #: 1
[All 300-710 Questions]

An engineer wants to connect a single IP subnet through a Cisco FTD firewall and enforce policy. There is a requirement to present the internal IP subnet to the outside as a different IP address. What must be configured to meet these requirements?

  • A. Configure the Cisco FTD firewall in routed mode with NAT enabled.
  • B. Configure the upstream router to perform NAT.
  • C. Configure the Cisco FTD firewall in transparent mode with NAT enabled.
  • D. Configure the downstream router to perform NAT.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Joe_Blue
Highly Voted 1 year, 5 months ago
Selected Answer: A
To meet the requirements of presenting the internal IP subnet as a different IP address while enforcing policy, the engineer needs to configure the Cisco FTD firewall with NAT. Option A is the correct answer: Configure the Cisco FTD firewall in routed mode with NAT enabled. Option D is also not the best solution because it would require configuring the downstream router to perform NAT, which may not be desirable or feasible in some environments.
upvoted 5 times
...
whysohardwhy
Most Recent 1 week, 1 day ago
Selected Answer: A
It reads like this is an edge firewall so A.
upvoted 1 times
...
Kris92
5 months, 4 weeks ago
Selected Answer: C
When they say single IP subnet, I think they mean a single network, so they are looking for transparent.
upvoted 1 times
MB2222
4 months ago
Not exactly, to represent any IP through 2 different interfaces (i.e. inside and outside), then NAT is required in conjunction with routed mode for traffic forwarding (TX/RX). So, the answer might be (A).
upvoted 1 times
...
...
LangaMos
1 year, 1 month ago
Im not happy with this statement ''P subnet to the outside as a different IP address''
upvoted 1 times
...
SegaMasterSystemAdmin
1 year, 2 months ago
Selected Answer: A
C. does not make any sense, just think about it for a second, if you have the same single subnet on both side of the FTD, why would you want to do NAT? The questions even states that "There is a requirement to present the internal IP subnet to the outside as a different IP address", so it needs to be a different IP address. FTD in routed mode with NAT enabled will accomplish this.
upvoted 4 times
...
THEODORABLE
1 year, 3 months ago
I am leaning towards A, they mention internal & outside networks in the question indicating that this could be on the Internet edge? If there were an edge router acting as CPE then I would say transparent but who is directly connected to the outside network?.
upvoted 1 times
...
Bbb78
1 year, 3 months ago
I agree is a sh*** cisco question but the answer is simple - only A meets the requirement. C do not make sense to me ?
upvoted 2 times
...
Initial14
1 year, 4 months ago
Selected Answer: C
Cisco being Cisco.... What a shitty question. The key here is one subnet. That means transparet firewall mode, and BVI will acts as proxy arp for that NAT-ed IP.
upvoted 1 times
...
Initial14
1 year, 5 months ago
Typical cisco, trying to complicate simple question. Instead of . The firewall in in routed/Transparent mode, they say An engineer wants to connect a single IP subnet THROUGH a Cisco FTD firewall and enforce policy. In my opinion that means transparent mode.
upvoted 2 times
...
tanri04
1 year, 5 months ago
maybe A? A. Configure the Cisco FTD firewall in routed mode with NAT enabled. To meet the requirements of presenting the internal IP subnet to the outside as a different IP address and enforcing policy, the Cisco FTD firewall should be configured in routed mode with Network Address Translation (NAT) enabled. This will allow the firewall to perform the necessary IP address translation while enforcing security policies on traffic passing through it. Configuring the upstream or downstream router to perform NAT would not allow for policy enforcement by the Cisco FTD firewall. Configuring the Cisco FTD firewall in transparent mode would not allow for IP address translation
upvoted 1 times
...
freho
1 year, 6 months ago
Selected Answer: C
Only C makes sense.
upvoted 1 times
...
Baumb
1 year, 6 months ago
Selected Answer: C
Based on the below comment and reading the manual, I think C is more appropriate.
upvoted 1 times
...
Mevijil
1 year, 6 months ago
Selected Answer: C
I vote C https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/network_address_translation_nat_for_firepower_threat_defense.html#ID-2091-0000034e
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago