ExamGecko
Question list
Search
Search

Related questions











Question 16 - 300-710 discussion

Report
Export

When deploying a Cisco ASA Firepower module, an organization wants to evaluate the contents of the traffic without affecting the network. It is currently configured to have more than one instance of the same device on the physical appliance Which deployment mode meets the needs of the organization?

A.

inline tap monitor-only mode

Answers
A.

inline tap monitor-only mode

B.

passive monitor-only mode

Answers
B.

passive monitor-only mode

C.

passive tap monitor-only mode

Answers
C.

passive tap monitor-only mode

D.

inline mode

Answers
D.

inline mode

Suggested answer: A

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/configuration/firewall/asa-910-firewall-config/access-sfr.htmlInline tap monitor-only mode (ASA inline)—In an inline tap monitor-only deployment, a copy of thetraffic is sent to the ASA FirePOWER module, but it is not returned to the ASA. Inline tap mode letsyou see what the ASA FirePOWER module would have done to traffic, and lets you evaluate thecontent of the traffic, without impacting the network.

However, in this mode, the ASA does apply itspolicies to the traffic, so traffic can be dropped due to access rules, TCP normalization, and so forth.

asked 07/10/2024
Marcelo Severo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first