exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 128 discussion

Actual exam question from Cisco's 350-701
Question #: 128
Topic #: 1
[All 350-701 Questions]


Refer to the exhibit. An administrator is adding a new Cisco FTD device to their network and wants to manage it with Cisco FMC. The Cisco FTD uses a registration key of Cisc392481137 and is not behind a NAT device. Which command is needed to enable this on the Cisco FTD?

  • A. configure manager add <FMC IP address> <registration key> 16
  • B. configure manager add DONTRESOLVE <registration key> FTD123
  • C. configure manager add <FMC IP address> <registration key>
  • D. configure manager add DONTRESOLVE <registration key>
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Luc_10
Highly Voted 3 years, 10 months ago
I think the correct answer is C, as this is stated in the Official Cert Guide: "When you add a managed device to the Cisco FMC, you must provide an IP addresses of the managed device along with a registration key for authentication. The Cisco FMC and the managed device use the registration key and a NAT ID (instead of IP addresses in the case that the device is behind NAT) to authenticate and authorize for initial registration." But in this case is not behind a NAT, so....C
upvoted 13 times
...
BennyTheK
Highly Voted 3 years, 9 months ago
The anwser is C. A is wrong (would need DONTRESOLVE to work in case on NAT device between FTD and FMC) B is wrong (would need 16 instead of FTD123, again in case on NAT device between FTD and FMC) C is correct:) D is wrong, DONTRESOLVE, KEY & NAT_ID is needed (again in case on NAT device between FTD and FMC)
upvoted 13 times
klu16
3 years, 8 months ago
Indeed! My vote also for option C ;)
upvoted 5 times
...
...
XvidalX
Most Recent 1 year, 1 month ago
Selected Answer: A
If you used a NAT ID during device setup, expand in the Advanced section and enter the same NAT ID in the Unique NAT ID field."
upvoted 2 times
...
LTLnetworker
1 year, 3 months ago
Selected Answer: A
FMC 6.6 guide: "If you used a NAT ID during device setup, expand in the Advanced section and enter the same NAT ID in the Unique NAT ID field."
upvoted 3 times
MPoels
1 year, 2 months ago
Correct (A), see https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/device_management_basics.html#ID-2242-0000069d
upvoted 1 times
...
XvidalX
1 year, 1 month ago
super agree
upvoted 1 times
BECAUSE
6 months, 2 weeks ago
Read the Question it states that the device is not behind a NAT device. The answer is C
upvoted 1 times
...
...
...
Ko13
1 year, 5 months ago
Selected Answer: A
A is correct, I worked with FTDs for a long time, even if there is no Nat device in between, if you use NAT ID on one side then you have to use it on the other side too, the exhibit has nat ID 16 on it so the FTD's command has to match it.
upvoted 4 times
KnackerTopf1
1 year, 5 months ago
i have tried this out in gns3, he's right, when specifying a nat id in the fmc, the nat id has to match on the device as well, otherwise it wont be able to communicate
upvoted 4 times
...
...
psuoh
2 years, 3 months ago
Selected Answer: C
Answer is C
upvoted 2 times
...
psuoh
2 years, 3 months ago
Selected Answer: C
https://w_w_w.youtube.com/watch?v=v_uZ9GbICBk
upvoted 1 times
...
psuoh
2 years, 3 months ago
Selected Answer: C
https://i.imgur.com/LdBgjED.png https://www.youtube.com/watch?v=v_uZ9GbICBk
upvoted 1 times
...
psuoh
2 years, 3 months ago
Selected Answer: C
https://www.youtube.com/watch?v=v_uZ9GbICBk https://i.imgur.com/LdBgjED.png
upvoted 1 times
...
harvey227
2 years, 8 months ago
C is correct answer. You don't need DONOTRESOLVE unless you are behind a NAT device. You need the NATID number.
upvoted 1 times
...
mecacig953
3 years, 1 month ago
Selected Answer: C
Syntax configure manager add {hostname | IPv4_address | IPv6_address | DONTRESOLVE} regkey [nat_id] where {hostname | IPv4_address | IPv6_address | DONTRESOLVE} specifies the DNS host name or IP address (IPv4 or IPv6) of the Firepower Management Center that manages this device. If the Firepower Management Center is not directly addressable, use DONTRESOLVE. If you useDONTRESOLVE, nat_id is required. regkey is the unique alphanumeric registration key required to register a device to the Firepower Management Center. nat_id is an optional alphanumeric string used during the registration process between the Firepower Management Center and the device. It is required if the hostname is set to DONTRESOLVE.
upvoted 1 times
...
brownbear505
3 years, 2 months ago
Selected Answer: C
Firepower Management Center Configuration Guide, Version 6.1 - Device Management Basics [Cisco Firepower Management Center] - Cisco
upvoted 1 times
...
u0815
3 years, 2 months ago
Selected Answer: C
100%, did it myself
upvoted 3 times
...
u0815
3 years, 2 months ago
Selected Answer: C
see Luc and all others
upvoted 1 times
...
NullNull88
3 years, 5 months ago
C is the correct answer ,..unless your FMC's IP address is "DONTRESOLVE" which makes zero sense at all and the questions says it is not behind NAT
upvoted 1 times
...
Dead_Adriano
3 years, 9 months ago
The answer is most probably C although it's not clear whe NAT ID is specified in FMC options. Regarding A: IP address + NAT ID can be specified on FTD in 2 cases: when FTD itself is behind NAT or when it's not but this is just another option to register device. But in both those cases IP of the device should be blank in FMC. This is explained here: https://www.cisco.com/c/en/us/td/docs/security/firepower/misc/fmc-ftd-mgmt-nw/fmc-ftd-mgmt-nw.html#ID-2242-00000191
upvoted 1 times
MoII
3 years, 5 months ago
If the FMC is behind a NAT device, enter a unique NAT ID along with the registration key, and specify DONTRESOLVE instead of the hostname, for example: Example: > configure manager add DONTRESOLVE regk3y78 natid90 If the FTD is behind a NAT device, enter a unique NAT ID along with the FMC IP address or hostname, for example: Example: > configure manager add 10.70.45.5 regk3y78 natid56 https://www.cisco.com/c/en/us/td/docs/security/firepower/misc/fmc-ftd-mgmt-nw/fmc-ftd-mgmt-nw.html#ID-2242-00000191 same link
upvoted 1 times
...
...
Dead_Adriano
3 years, 9 months ago
Funny thing is that the question says "F_T_D is not behind NAT", although DONTRESOLVE should be used when F_M_C is NATted. But anyway DONTRESOLVE must be used with nat_id, and there is no such answer here.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago