300-710 · Question #417
An engineer is configuring a multidomain instance of Cisco Secure Firewall Management Center. The instance must be integrated with Cisco Secure Endpoint. What must the engineer configure to allow…
The correct answer is B. leaf domain. To allow multiple domains in a multidomain Cisco Secure Firewall Management Center instance to have hosts with the same IP-MAC address pairs, the engineer must configure the domains as 'leaf domains'.
Question
An engineer is configuring a multidomain instance of Cisco Secure Firewall Management Center. The instance must be integrated with Cisco Secure Endpoint. What must the engineer configure to allow multiple domains to have hosts with the same IP-MAC address pairs?
Options
- Asecond-level domain
- Bleaf domain
- Cglobal domain
- Dsubdomain
How the community answered
(57 responses)- A7% (4)
- B79% (45)
- C12% (7)
- D2% (1)
Why each option
To allow multiple domains in a multidomain Cisco Secure Firewall Management Center instance to have hosts with the same IP-MAC address pairs, the engineer must configure the domains as 'leaf domains'.
A 'second-level domain' is a generic DNS term and not a specific configuration within FPMC for handling duplicate IP-MAC addresses in a multi-domain setup.
In a multi-domain deployment of Cisco Secure Firewall Management Center, configuring domains as leaf domains is essential for allowing duplicate IP-MAC address pairs across different domains. This capability is critical for environments where separate tenants or departments may utilize overlapping IP address spaces or have devices with identical MAC addresses behind different firewalls, ensuring proper integration with services like Cisco Secure Endpoint that rely on unique host identification within their respective contexts.
The 'global domain' in FPMC is the top-level domain that typically mandates unique IP-MAC addresses across its entire scope; it does not enable duplicates for subordinate domains.
A 'subdomain' is a generic networking term and not a specific FPMC domain type that allows for duplicate IP-MAC address handling across different administrative domains.
Concept tested: Cisco Secure Firewall Management Center multi-domain architecture
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/multi-domain-management.html
Topics
Community Discussion
No community discussion yet for this question.