exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 133 discussion

Actual exam question from Cisco's 350-701
Question #: 133
Topic #: 1
[All 350-701 Questions]

An organization deploys multiple Cisco FTD appliances and wants to manage them using one centralized solution. The organization does not have a local VM but does have existing Cisco ASA that must migrate over to Cisco FTDs. Which solution meets the needs of the organization?

  • A. Cisco FMC
  • B. CDO
  • C. CSM
  • D. Cisco FDM
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
eazy99
Highly Voted 3 years, 7 months ago
What a tricky question, but I think I just got you the perfect answer and the perfect link from Cisco. The correct answer is A, not B. The reason why, According to Cisco, if you want to migrate your ASA to FTD and want to manage them both through "CDO and FDM" then use (CDO), but if you want to migrate ASA to FTD and manage both in the same time (Centralized) then use FMC" So the answer is absolutely A, and here is the link: https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-CDO/ASA2FTD_Using_CDO/ASA2FTD_with_FP_Migration_Tool_cdo_chapter_011.html
upvoted 24 times
loser4fun
2 years, 1 month ago
but there's another tricky part which is the organization doesn't have a local VM which makes the answer is B
upvoted 4 times
MPoels
1 year, 2 months ago
Answer A seems to be right (with a physical FMC appliance). Official ASA-2-FTD migration tool exists several years (so CDO built-in migration tool isn't needed): https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/b_Migration_Guide_ASA2FTD_chapter_00.html Consideration why not using CDO (in this scenario): When using device credentials to connect CDO to a device, it is a best practice to download and deploy an SDC in your network to manage the communication between CDO and the device. This procedure describes how to install an SDC in your network, using CDO's VM image. This is the preferred, easiest, and most reliable way to create an SDC. (see https://docs.defenseorchestrator.com/r_how-it-works_cdo.html#!t_deploy-a-sdc-using-cdos-vm-image.html)
upvoted 3 times
...
angry
2 years, 1 month ago
you can have physical FMC deployment. A is correct!
upvoted 5 times
...
gc999
2 years, 1 month ago
Just want to confirm that FMC can also support Cloud Deployment. Right? https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html
upvoted 2 times
...
...
...
semi1750
Highly Voted 3 years ago
Vote for B FMC will manage only Firepower images (FTD or Firepower module Services). CDO is able to centrally manage your ASAs, FTD, Meraki security policies and AWS VPC security policies. For FMC, you need to have a local VM (with some resources like 32G RAM) and need to manage the redundancy as well. CDO is cloud based (could have a local VM with small resources to communicate with the cloud and not expose your devices management). You need to see CDO like the Meraki portal for Cisco Security Firewalls. https://community.cisco.com/t5/network-security/a-classic-cdo-vs-fmc/td-p/4070116
upvoted 8 times
...
luismg
Most Recent 7 months, 2 weeks ago
Selected Answer: B
I would say is CDO because FMC is usually a VM.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: B
It is CDO, which can migrate from ASA to FTD. Cisco FMC is a fairly new thing, where Cisco hosts the FMC for you, since that thing is supposed to have around 30GB of memory, even when managing one or two FTD devices. Also, FMC cannot migrate from ASA to FTD, you have to re-enter the entire configuration from scratch.
upvoted 3 times
...
Ko13
1 year, 5 months ago
Selected Answer: B
It is B. CDO . The FMC cannot help with the ASA-to-FTD migration, you do that using the Firepower Migration Tool, then the config is loaded in to the FMC once migrated. CDO on the other hand does allow you to migrate ASA to FTD (managed using FDM thou), but it also allows you to then manage thouse FDM FTDs too. https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-CDO/ASA2FTD_Using_CDO/ASA2FTD_with_FP_Migration_Tool_cdo_chapter_011.html https://www.cisco.com/c/en/us/td/docs/security/cdo/managing-ftd-with-cdo/managing-ftd-with-cisco-defense-orchestrator/managing-ftd-with-cdo.html
upvoted 1 times
...
DWizard
1 year, 10 months ago
Selected Answer: A
The answer can be A) FMC using an appliance, not a virtual machine, or B) CDO without SDCs... it's a hard one, but I would go for A, has more sense if it must be a "centralized solution"
upvoted 2 times
...
ffaiz
1 year, 10 months ago
Selected Answer: B
"The organization does not have a local VM" 1-FDM(manage device locally ) 2-CDO(cloud based central management no need VM) 3-FMC(VM based central management)
upvoted 2 times
...
Jessie45785
1 year, 10 months ago
Selected Answer: B
It is Cisco question do not overthink it - if you cannot use VM you are left with CDO https://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa2ftd-migration/asa2ftd-migration-guide-620/asa2ftd_migration_procedure.pdf FMC: Step 1 Download one of the following images from Support: • Firepower Management Center Virtual for VMware • Firepower Management Center Virtual for KVM Step 2 Use the image file to install a dedicated Firepower Management Center Virtual, as described in the appropriate guide: • Cisco Firepower Management Center Virtual for VMware Deployment Quick Start Guide • Cisco Firepower Management Center Virtual for KVM Deployment Quick Start Guide Step 3 Connect to the Firepower Management Center via ssh, using the admin username. Step 4 Log in to the root shell: sudo su - Step 5 Run the following command: enableMigrationTool.pl After the process completes, refresh any web interface sessions running on the Firepower Management Center to use the migration tool.
upvoted 2 times
...
littlewilly
1 year, 11 months ago
Selected Answer: B
Answer is CDO
upvoted 1 times
...
alexyozgat24
1 year, 11 months ago
i came cross this situation for deploying FPR1150 firewalls. basically you will have 3 options 1-FDM(manage device locally ) 2-CDO(cloud based central management no need VM) 3-FMC(VM based central management) so for this question you need to manage them from controller but not from the VM you manage, answer is CDO . so B.
upvoted 3 times
...
KPzee
2 years, 1 month ago
A is correct. FMC supports both physical and virtual appliances, hence it can be deployed as a virtual machine on an existing server infrastructure or as a physical appliance. also FMC supports the migration of Cisco ASA configurations to Cisco FTD
upvoted 1 times
...
Tuxzinator
2 years, 2 months ago
Selected Answer: A
B is incorrect. CDO (Cisco Defense Orchestrator) is a cloud-based management solution that can manage multiple Cisco security products, including ASA (Adaptive Security Appliance) and FTD. However, it requires a local VM to be deployed in order to manage on-premises devices.
upvoted 3 times
DWizard
1 year, 10 months ago
No, as long as those on-premises devices have Internet access https://www.cisco.com/c/en/us/td/docs/security/cdo/managing-asa-with-cdo/managing-asa-with-cisco-defense-orchestrator/basics-of-cisco-defense-orchestrator.html
upvoted 1 times
...
...
Emlia1
2 years, 4 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
Hereim
2 years, 6 months ago
I will go with B. Very good comparison between CDO and FMC pros and cons in this link https://community.cisco.com/t5/network-security/a-classic-cdo-vs-fmc/td-p/4070116 Main two points here to note: there is no local VM as per the question. FMC needs a local VM. Secondly, the question clearly says the existing ASA must migrate over to FTD - CDO can do that however FMC you need to do separate migration tool.
upvoted 4 times
gc999
1 year, 11 months ago
But here said that FMC can be deployed either physical or virtual, or from the Cloud. https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html
upvoted 2 times
...
...
sis_net_sec
2 years, 6 months ago
Selected Answer: A
cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/firepower_threat_defense_logical_devices.html
upvoted 1 times
...
xxx_ford
2 years, 9 months ago
Is B as it states ASA to FTD migration CDO can be used.
upvoted 2 times
...
NikoNiko
2 years, 9 months ago
It's B - CDO. "organization deploys multiple Cisco FTD appliances and WANTS TO manage" - i. e. is NOT managing it now but wants to do it (probably) in the future. "organization does not have a local VM" - i. e. no place for FMC deployment, "ave existing Cisco ASA that must migrate over to Cisco FTDs" - just another feason for CDO and its migration tool
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago