exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 114 discussion

Actual exam question from Cisco's 300-710
Question #: 114
Topic #: 1
[All 300-710 Questions]

An organization has a Cisco IPS running in inline mode and is inspecting traffic for malicious activity. When traffic is received by the Cisco IPS, if it is not dropped, how does the traffic get to its destination?

  • A. It is retransmitted from the Cisco IPS inline set
  • B. The packets are duplicated and a copy is sent to the destination
  • C. It is transmitted out of the Cisco IPS outside interface
  • D. It is routed back to the Cisco ASA interfaces for transmission
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
eazy99
Highly Voted 1 year, 7 months ago
Selected Answer: A
The Answer is absolutely A. "Inline interfaces receive all traffic unconditionally, but all traffic received on these interfaces is retransmitted out of an inline set unless explicitly dropped." You can verify my answer here: https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/fpmc-config-guide-v60_chapter_01011010.pdf The third page, under (Inline IPS Deployments)
upvoted 7 times
...
d0980cc
Most Recent 2 months ago
Selected Answer: C
If the Cisco IPS in inline mode does not drop the traffic after inspection, it forwards the traffic directly to its destination via its outbound interface, but after reading the article below I will select A.
upvoted 1 times
...
THEODORABLE
5 months, 3 weeks ago
I believe D is correct, its just a poor choice of words....go figure. No matter if it is the Cisco IPS or and FTD the traffic is handed back to the LINA engine to be put out on the wire based on the SNORT verdict. Although the CISCO IPS no longer exist (TG!)
upvoted 3 times
Silexis
3 months, 1 week ago
I was on the same line of thoughts with but they used the word "routed", which is not the case. Unfortunately these kind of questions are no longer testing candidates knowledge but are testing the focus capacity on phrasing, which in my opinion it is bad!
upvoted 1 times
...
...
Joe_Blue
8 months ago
Selected Answer: A
If traffic is not dropped by the Cisco IPS running in inline mode, the packets are retransmitted from the IPS inline set to the original destination. So, the correct option is A.
upvoted 1 times
...
xziomal9
1 year, 4 months ago
Selected Answer: A
Correct answer is: A
upvoted 1 times
...
Reece_S
1 year, 6 months ago
I believe D is correct. The fact the question says Cisco IPS and not Cisco Firepower, it is probably an ASA. I don't think it has inline set interfaces as an option, only inline and tap mode. Traffic that's not dropped goes Lina -> Snort -> and back to Lina for transmission to the destination even in FTD. And the question is asking how it reaches the destination as well. If the question said Cisco FTD, it would definitely be onboard with A as the answer.
upvoted 4 times
Gabranch
5 months, 2 weeks ago
Perhaps - But the test outline has all Firepower topics, not ASA+FP
upvoted 2 times
...
...
ERGEGA
1 year, 8 months ago
In an FTD in inline mode, if the traffic is not droped is retransmited out from the inlineset pair interfaces.
upvoted 1 times
...
NoOn3x
1 year, 9 months ago
And why not C? It mentions that the IPS transmits it through the outside interface, which would be the interface through which the traffic belonging to the Inline-set will go out.
upvoted 1 times
trickbot
1 year, 8 months ago
C is not the best answer. You have to make a couple unconventional assumptions about the outside interface for C to correct. Such as, "Outside" interface kind of implies the connection to your ISP, which is a routed interface. (see others below on that.)
upvoted 1 times
...
...
ion123
1 year, 10 months ago
Selected Answer: A
The IPS-only (inline mode) does not have routing possibilities. So, A is correct
upvoted 2 times
...
onefa
2 years ago
Must be A IPS-only interfaces can be deployed as the following types: Inline Set, with optional Tap mode—An inline set acts like a bump on the wire, and binds two interfaces together to slot into an existing network. This function allows the FTD to be installed in any network environment without the configuration of adjacent network devices. Inline interfaces receive all traffic unconditionally, but all traffic received on these interfaces is retransmitted out of an inline set unless explicitly dropped.
upvoted 3 times
...
elliot67
2 years ago
The IPS-only (inline mode) does not have routing possibilities. So, A is correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago