300-710 · Question #314
An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified. Which set of…
The correct answer is A. Set the interface mode to passive. Associate the interface with a security zone. Enable the. In a passive IPS deployment, the FTD interface receives a copy of traffic (via a SPAN or TAP port) and inspects it without being inline in the traffic path. The required configuration steps are: (1) Set the interface mode to Passive, (2) Associate the interface with a security…
Question
An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified. Which set of configuration steps must the administrator perform next to complete the implementation?
Options
- ASet the interface mode to passive. Associate the interface with a security zone. Enable the
- BModify the interface to retransmit received traffic. Associate the interface with a security zone Set
- CSet the interface mode to passive. Associate the interface with a security zone. Set the MTU
- DModify the interface to retransmit received traffic. Associate the interface with a security zone.
How the community answered
(57 responses)- A77% (44)
- B5% (3)
- C4% (2)
- D14% (8)
Explanation
In a passive IPS deployment, the FTD interface receives a copy of traffic (via a SPAN or TAP port) and inspects it without being inline in the traffic path. The required configuration steps are: (1) Set the interface mode to Passive, (2) Associate the interface with a security zone (required for policy matching), and (3) Enable the interface. Passive mode interfaces do not transmit or retransmit traffic - they only listen. Options B and D that mention 'retransmit received traffic' describe inline behavior, not passive. Option C mentions configuring MTU, which is not a required step specific to passive deployments. Setting the MTU is optional configuration and not part of the mandatory passive IPS setup sequence.
Topics
Community Discussion
No community discussion yet for this question.