exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 43 discussion

Actual exam question from Cisco's 300-710
Question #: 43
Topic #: 1
[All 300-710 Questions]

What are two features of bridge-group interfaces in Cisco FTD? (Choose two.)

  • A. The BVI IP address must be in a separate subnet from the connected network.
  • B. Bridge groups are supported in both transparent and routed firewall modes.
  • C. Bridge groups are supported only in transparent firewall mode.
  • D. Bidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-group members.
  • E. Each directly connected network must be on the same subnet.
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bobster02
Highly Voted 2 years, 6 months ago
C and D are the wrong answers. Must be B and E. Cisco FMC config guide v 6.2 states that: Bridge Group Guidelines (Transparent and Routed Mode): You can create up to 250 bridge groups, with 64 interfaces per bridge group. Each directly-connected network must be on the same subnet.
upvoted 11 times
...
lollo1234
Highly Voted 2 years, 5 months ago
"Bridge groups are supported in both transparent and routed firewall mode" "Each directly-connected network must be on the same subnet." https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html
upvoted 8 times
...
Lautaros
Most Recent 6 months, 2 weeks ago
The anser Highlighted are C and D, and should be B and E.
upvoted 1 times
...
THEODORABLE
6 months, 3 weeks ago
B & E -- https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/fpmc-config-guide-v61_chapter_01110000.pdf Bidirectional Forwarding Detection (BFD) echo packets are not allowed through the FTD when using bridge group members. If there are two neighbors on either side of the FTD running BFD, then the FTD will drop BFD echo packets because they have the same source and destination IP address and appear to be part of a LAND attack.
upvoted 1 times
...
xziomal9
1 year, 5 months ago
Selected Answer: BE
Correct answer is: B and E
upvoted 2 times
...
anwar1
1 year, 6 months ago
C is correct as per below Cisco config guide "About Bridge Groups". However, Bridge group traffic can be routed to other bridge groups or routed interfaces. You can choose to isolate bridge group traffic by not assigning a name to the BVI interface for the bridge group. If you name the BVI, then the BVI participates in routing like any other regular interface. https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/fpmc-config-guide-v61_chapter_01110000.pdf
upvoted 1 times
anwar1
1 year, 6 months ago
D is definitely wrong as explicitly mentioned in same document. Check "Guidelines for Firewall Mode".
upvoted 1 times
...
anwar1
1 year, 6 months ago
My answer is C and E as explicitly mentioned in same document "Guidelines for Firewall Mode".
upvoted 1 times
...
...
Miksik
1 year, 9 months ago
Selected Answer: BE
Must be BE
upvoted 2 times
...
liqucika
1 year, 10 months ago
Selected Answer: BE
Supported in both modes and must be the same subnet.
upvoted 3 times
...
kakakayayaya
2 years, 6 months ago
Completely wrong answer BVI supported in R and T mode and have to be same subnet as connected network.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...