Cisco FTD Interface Mode for SPAN Deployment

Answer Correct answer: C — Set the interface mode to none, and configure an access control policy with an intrusion policy and a file policy defined.

An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats. When setting the Cisco FTD interface mode, which sequence of actions meets this requirement?

  1. Set to passive, and configure an access control policy with an intrusion policy and a file policy defined.
  2. Set to passive, and configure an access control policy with a prefilter policy defined.
  3. Set to none, and configure an access control policy with an intrusion policy and a file policy defined. Correct Answer
  4. Set to none, and configure an access control policy with a prefilter policy defined.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

To configure a passive SPAN interface in FMC, the physical interface mode must be set to None, not Passive, before being assigned to a passive interface object.

Deploying a Cisco FTD appliance to span a network segment requires setting the interface mode to None and applying an access control policy with intrusion and file policies. This page explains why option C is the correct configuration for passive threat detection.

Choosing A because 'span' implies passive mode, but the interface mode drop-down in FMC does not have a 'Passive' option; it must be set to 'None' first.

Community Discussion (3 comments)

tinyJoe 👍 1 Selected: C
The answer is definitely C, not A. First, “span a network segment” indicates that the mode of FTD itself is routed, not transparent, and that the interface to each segment must be assigned an IP address. Interfaces in passive mode cannot be assigned an IP address; they must be in none mode in order to be assigned an IP address.
rbrain 👍 1 Selected: C
" An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats" to span a network is setting up the device as a bump in the road where to interfaces are connected and traffic is passing through the device. To do so the interface mode should be set to none and not passive
Doris8000 👍 1
looks ok

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When configuring a Cisco FTD appliance for a SPAN or tap deployment via FMC, the physical interface must be set to the "None" mode before it can be added to a passive interface logical object. Furthermore, to detect both malware and threats on a spanned segment, the applied access control policy must include both an intrusion policy (for threats) and a file policy (for malware). Option C correctly specifies setting the interface mode to None and configuring these required policies.

Why the Other Options Are Wrong

Options A and B suggest setting the interface mode to "passive," which is invalid because the FMC interface configuration dropdown only offers Routed, Transparent, and None; passive is a logical interface type, not a base mode. Option D suggests using a prefilter policy, which is primarily used for early blocking or fast-pathing traffic in inline deployments, but in a passive (SPAN) deployment, the system cannot block traffic and relies on intrusion and file policies for detection.

Community Comment Notes

Commenters correctly identified that the interface mode must be set to "none" rather than "passive," noting that "Interfaces in passive mode cannot be assigned an IP address; they must be in none mode." Another user highlighted that "to span a network is setting up the device as a bump in the road" but correctly concluded the interface mode should be set to none. The key takeaway from the community is the recognition of the FMC interface mode limitations for SPAN deployments.

Official Reference

Exam Strategy

Remember that FMC does not have a "Passive" option in the physical interface mode dropdown; you must select "None" and assign it to a passive logical interface. Also, associate passive deployments with detection (intrusion and file policies) rather than blocking.

Related Analysis

← Back to 300-710 Study Guide