nerdexam
Cisco

300-710 · Question #314

An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified. Which set of…

The correct answer is A. Set the interface mode to passive. Associate the interface with a security zone. Enable the. In a passive IPS deployment, the FTD interface receives a copy of traffic (via a SPAN or TAP port) and inspects it without being inline in the traffic path. The required configuration steps are: (1) Set the interface mode to Passive, (2) Associate the interface with a security…

Configuration

Question

An administrator is configuring the interface of a Cisco Secure Firewall Threat Defense firewall device in a passive IPS deployment. The device and interface have been identified. Which set of configuration steps must the administrator perform next to complete the implementation?

Options

  • ASet the interface mode to passive. Associate the interface with a security zone. Enable the
  • BModify the interface to retransmit received traffic. Associate the interface with a security zone Set
  • CSet the interface mode to passive. Associate the interface with a security zone. Set the MTU
  • DModify the interface to retransmit received traffic. Associate the interface with a security zone.

How the community answered

(57 responses)
  • A
    77% (44)
  • B
    5% (3)
  • C
    4% (2)
  • D
    14% (8)

Explanation

In a passive IPS deployment, the FTD interface receives a copy of traffic (via a SPAN or TAP port) and inspects it without being inline in the traffic path. The required configuration steps are: (1) Set the interface mode to Passive, (2) Associate the interface with a security zone (required for policy matching), and (3) Enable the interface. Passive mode interfaces do not transmit or retransmit traffic - they only listen. Options B and D that mention 'retransmit received traffic' describe inline behavior, not passive. Option C mentions configuring MTU, which is not a required step specific to passive deployments. Setting the MTU is optional configuration and not part of the mandatory passive IPS setup sequence.

Topics

#Passive IPS#FTD Interface Configuration#Security Zones#IPS Policy

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice