exam questions

Exam 300-710 All Questions

View all questions & answers for the 300-710 exam

Exam 300-710 topic 1 question 148 discussion

Actual exam question from Cisco's 300-710
Question #: 148
Topic #: 1
[All 300-710 Questions]

An administrator is configuring their transparent Cisco FTD device to receive ERSPAN traffic from multiple switches on a passive port, but the Cisco FTD is not processing the traffic. What is the problem?

  • A. The switches do not have Layer 3 connectivity to the FTD device for GRE traffic transmission.
  • B. The switches were not set up with a monitor session ID that matches the flow ID defined on the Cisco FTD.
  • C. The Cisco FTD must be in routed mode to process ERSPAN traffic.
  • D. The Cisco FTD must be configured with an ERSPAN port not a passive port.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Silexis
3 months, 1 week ago
Selected Answer: C
ERSPAN can be configured only when FTD is in ROUTED MODE
upvoted 1 times
...
MB2222
6 months, 3 weeks ago
Answer is (C). See section "Guidelines for Inline Sets and Passive Interfaces" Firewall Mode - ERSPAN interfaces are only allowed when the device is in routed firewall mode. https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/inline_sets_and_passive_interfaces_for_firepower_threat_defense.html#id_19616
upvoted 4 times
...
achille5
8 months, 1 week ago
Selected Answer: C
The Cisco ERSPAN feature allows you to monitor traffic on ports or VLANs and send the monitored traffic to destination ports. The ERSPAN feature requires IP routing to be enabled in the Global Configuration Mode. https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9400/software/release/16-6/configuration_guide/nmgmt/b_166_nmgmt_9400_cg/b_166_nmgmt_9400_cg_chapter_01000.pdf
upvoted 2 times
...
cla8829
1 year, 5 months ago
A & C Passive or ERSPAN Passive—Passive interfaces monitor traffic flowing across a network using a switch SPAN or mirror port. The SPAN or mirror port allows for traffic to be copied from other ports on the switch. This function provides the system visibility within the network without being in the flow of network traffic. When you configure the FTD in a passive deployment, the FTD cannot take certain actions such as blocking or shaping traffic. Passive interfaces receive all traffic unconditionally. and no traffic received on these interfaces is retransmitted. Encapsulated remote switched port analyzer (ERSPAN) interfaces allow you to monitor traffic from source ports distributed over multiple switches, and uses GRE to encapsulate the traffic. ERSPAN interfaces are only allowed when the FTD is in routed firewall mode.
upvoted 3 times
...
Bbb78
1 year, 5 months ago
Selected Answer: D
Not sure its C .... " To process ERSPAN traffic, an FTD device should have an ERSPAN interface configured. The ERSPAN interface is specifically designed to receive and decode ERSPAN traffic. The ERSPAN interface can be connected to an ERSPAN source port on a switch or other devices to capture and analyze the encapsulated ERSPAN traffic."
upvoted 1 times
Bbb78
1 year, 5 months ago
Disregard - this FTD is in transparent mode ....sorry did not saw that. Option C is correct.
upvoted 2 times
...
...
Initial14
1 year, 7 months ago
Selected Answer: C
The firewall must be in routed mode for ERSPAN
upvoted 2 times
...
Joe_Blue
1 year, 8 months ago
Selected Answer: C
Guidelines for Inline Sets and Passive Interfaces Firewall Mode ERSPAN interfaces are only allowed when the device is in routed firewall mode.
upvoted 2 times
...
lapsi
1 year, 8 months ago
Isn't it C. refer: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/inline_sets_and_passive_interfaces_for_firepower_threat_defense.html "ERSPAN interfaces are only allowed when the FTD is in routed firewall mode"
upvoted 2 times
...
Seawanderer
1 year, 9 months ago
Selected Answer: A
It's A. If not already in routed mode, the interfaced couldn't be configured
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago