nerdexam
Cisco

300-710 · Question #415

An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the…

The correct answer is A. Passive mode. Passive mode deploys the FTD device as a traffic sensor connected to a SPAN port or network tap. Traffic is copied to the sensor for analysis, but the sensor is completely out-of-band-it never sits in the traffic path. This means intrusion events can be detected and alerted on…

Deployment

Question

An engineer is configuring two new Cisco Secure Firewall Threat Defense devices to replace the existing firewalls. Network traffic must be analyzed for intrusion events without impacting the traffic. What must the engineer implement next to accomplish the goal?

Options

  • APassive mode
  • BInline Pair in Tap mode
  • CERSPAN Passive mode
  • DInline Pair mode

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    2% (1)
  • C
    2% (1)
  • D
    7% (3)

Explanation

Passive mode deploys the FTD device as a traffic sensor connected to a SPAN port or network tap. Traffic is copied to the sensor for analysis, but the sensor is completely out-of-band-it never sits in the traffic path. This means intrusion events can be detected and alerted on without any possibility of dropping, delaying, or impacting live traffic. Inline Pair mode (D) places the device in the traffic path and can drop packets. Inline Pair in Tap mode (B) is an Inline mode that mimics passive behavior but still uses an inline configuration. ERSPAN Passive mode (C) uses encapsulated remote SPAN but is less common and not the primary answer here.

Topics

#Cisco Secure Firewall Threat Defense#Deployment Modes#Passive Mode#Intrusion Detection

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice