nerdexam
Cisco

300-710 · Question #427

A network administrator manages a network with multiple firewalls in a datacenter using Cisco Secure Firepower Management Center. The administrator must change a next-generation firewall from routed…

The correct answer is A. Deregister the firewall in Cisco Secure Firewall Management Center. To change a Cisco Secure Firewall Threat Defense device from routed to transparent mode when it is managed by Cisco Secure Firepower Management Center, the administrator must first deregister the firewall from FMC.

Management and Troubleshooting

Question

A network administrator manages a network with multiple firewalls in a datacenter using Cisco Secure Firepower Management Center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take next to meet the requirement?

Options

  • ADeregister the firewall in Cisco Secure Firewall Management Center.
  • BEnter the configure transparent firewall command from the CLI.
  • CCreate one or more bridge groups from the CLI.
  • DManually delete the interface configuration from the CLI.

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    4% (1)
  • C
    17% (4)
  • D
    8% (2)

Why each option

To change a Cisco Secure Firewall Threat Defense device from routed to transparent mode when it is managed by Cisco Secure Firepower Management Center, the administrator must first deregister the firewall from FMC.

ADeregister the firewall in Cisco Secure Firewall Management Center.Correct

When a Cisco Secure Firewall Threat Defense (FTD) device is managed by a Firepower Management Center (FMC), certain fundamental changes, such as switching between routed and transparent mode, require the device to be deregistered from the FMC first. This allows the administrator to perform the mode change locally on the FTD device's CLI before re-registering it with the FMC for centralized management.

BEnter the configure transparent firewall command from the CLI.

While the `configure transparent` command is used on the FTD CLI to change modes, it cannot be executed directly when the device is under FMC management without prior deregistration.

CCreate one or more bridge groups from the CLI.

Creating bridge groups is a configuration step performed after the firewall is successfully in transparent mode, not the prerequisite action to initiate the mode change itself.

DManually delete the interface configuration from the CLI.

Manually deleting interface configurations from the CLI may be part of a broader reconfiguration, but it is not the primary 'next' action required to change an FMC-managed FTD device's operational mode.

Concept tested: Cisco Secure Firewall FTD mode change

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/get-started-with-firepower-threat-defense.html#ID-2313-000000e3

Topics

#Firepower Management Center (FMC)#Firewall Modes#Device Management#FTD Reconfiguration

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice