Cisco FTD Interface Mode for SPAN Deployment
An engineer must deploy a Cisco FTD appliance via Cisco FMC to span a network segment to detect malware and threats. When setting the Cisco FTD interface mode, which sequence of actions meets this requirement?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
To configure a passive SPAN interface in FMC, the physical interface mode must be set to None, not Passive, before being assigned to a passive interface object.
Deploying a Cisco FTD appliance to span a network segment requires setting the interface mode to None and applying an access control policy with intrusion and file policies. This page explains why option C is the correct configuration for passive threat detection.
Choosing A because 'span' implies passive mode, but the interface mode drop-down in FMC does not have a 'Passive' option; it must be set to 'None' first.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
When configuring a Cisco FTD appliance for a SPAN or tap deployment via FMC, the physical interface must be set to the "None" mode before it can be added to a passive interface logical object. Furthermore, to detect both malware and threats on a spanned segment, the applied access control policy must include both an intrusion policy (for threats) and a file policy (for malware). Option C correctly specifies setting the interface mode to None and configuring these required policies.Why the Other Options Are Wrong
Options A and B suggest setting the interface mode to "passive," which is invalid because the FMC interface configuration dropdown only offers Routed, Transparent, and None; passive is a logical interface type, not a base mode. Option D suggests using a prefilter policy, which is primarily used for early blocking or fast-pathing traffic in inline deployments, but in a passive (SPAN) deployment, the system cannot block traffic and relies on intrusion and file policies for detection.Community Comment Notes
Commenters correctly identified that the interface mode must be set to "none" rather than "passive," noting that "Interfaces in passive mode cannot be assigned an IP address; they must be in none mode." Another user highlighted that "to span a network is setting up the device as a bump in the road" but correctly concluded the interface mode should be set to none. The key takeaway from the community is the recognition of the FMC interface mode limitations for SPAN deployments.Official Reference
Exam Strategy
Remember that FMC does not have a "Passive" option in the physical interface mode dropdown; you must select "None" and assign it to a passive logical interface. Also, associate passive deployments with detection (intrusion and file policies) rather than blocking.