nerdexam
Cisco

300-710 · Question #225

A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to…

The correct answer is A. inline set pair C. tap mode. To deploy a Cisco FTD inline as a bump in the wire for intrusion detection without disrupting traffic, an inline set pair must be configured with tap mode enabled.

Deployment

Question

A security engineer must deploy a Cisco FTD appliance as a bump in the wire to detect intrusion events without disrupting the flow of network traffic. Which two features must be configured to accomplish the task? (Choose two.)

Options

  • Ainline set pair
  • Btransparent mode
  • Ctap mode
  • Dpassive interfaces
  • Ebridged mode

How the community answered

(59 responses)
  • A
    85% (50)
  • B
    8% (5)
  • D
    5% (3)
  • E
    2% (1)

Why each option

To deploy a Cisco FTD inline as a bump in the wire for intrusion detection without disrupting traffic, an inline set pair must be configured with tap mode enabled.

Ainline set pairCorrect

An inline set pair configures two physical interfaces on the FTD to act as a single logical connection, allowing traffic to flow directly through the appliance. This establishes the 'bump in the wire' inline deployment.

Btransparent mode

Transparent mode is an inline deployment, but it actively inspects and potentially blocks traffic, which could disrupt flow if bypass is not configured or if the device fails without a hardware bypass.

Ctap modeCorrect

Tap mode, when applied to an inline set, configures the FTD to passively monitor all traffic passing through the inline interfaces for intrusion events without actively blocking or modifying it. This ensures that network traffic continues to flow uninterrupted, even if threats are detected, fulfilling the requirement of detecting intrusion events without disruption.

Dpassive interfaces

Passive interfaces are for out-of-band monitoring of mirrored traffic, not for a 'bump in the wire' inline deployment.

Ebridged mode

Bridged mode is another term for transparent mode, which actively inspects and potentially blocks traffic, contrary to the 'without disrupting flow' requirement.

Concept tested: Cisco FTD inline set with tap mode deployment

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/6x/configuration/guide/fpmc-config-guide-v6x/interface_configuration.html

Topics

#FTD Deployment Modes#Intrusion Detection#Inline vs. Passive#Traffic Monitoring

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice