300-710 · Question #415
An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the…
The correct answer is A. Passive mode. Passive mode deploys the FTD device as a traffic sensor connected to a SPAN port or network tap. Traffic is copied to the sensor for analysis, but the sensor is completely out-of-band-it never sits in the traffic path. This means intrusion events can be detected and alerted on…
Question
An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the traffic. What must the engineer implement next to accomplish the goal?
Options
- APassive mode
- BInline Pair in Tap mode
- CERSPAN Passive mode
- DInline Pair mode
How the community answered
(42 responses)- A88% (37)
- B2% (1)
- C2% (1)
- D7% (3)
Explanation
Passive mode deploys the FTD device as a traffic sensor connected to a SPAN port or network tap. Traffic is copied to the sensor for analysis, but the sensor is completely out-of-band-it never sits in the traffic path. This means intrusion events can be detected and alerted on without any possibility of dropping, delaying, or impacting live traffic. Inline Pair mode (D) places the device in the traffic path and can drop packets. Inline Pair in Tap mode (B) is an Inline mode that mimics passive behavior but still uses an inline configuration. ERSPAN Passive mode (C) uses encapsulated remote SPAN but is less common and not the primary answer here.
Topics
Community Discussion
No community discussion yet for this question.