What is the Firewall Mode with a Named BVI?

Implement Secure Firewall modes
Answer Correct answer: B — assigning physical interfaces to a named BVI indicates the Cisco Secure Firewall Threat Defense is in routed mode.

Which firewall mode is Cisco Secure Firewall Threat Defense in when two physical interfaces are assigned to a named BVI?

  1. IPS only
  2. routed Correct Answer
  3. transparent
  4. in-line

Community Votes

B
50%
C
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the difference in BVI configuration between firewall modes; the trap is assuming any BVI means transparent mode, but only a named BVI indicates routed mode.

In Cisco Secure Firewall Threat Defense, assigning physical interfaces to a named Bridge Virtual Interface (BVI) indicates the device is operating in routed firewall mode. This page explains the distinction between BVI usage in routed versus transparent modes.

Choosing transparent (C) because BVIs are heavily used for bridge groups in transparent mode, overlooking that transparent mode BVIs cannot be named.

Community Discussion (3 comments)

Andy0724 👍 2 Selected: C
To configure a transparent firewall, we have to configure the bridge group and add interfaces to that bridge group. In transparent mode each bridge group is separate and not communicate with each other. FirePower threat defence (FTD) system use bridging technique to pass traffic between interfaces. Each bridge group includes Bridge virtual interface (BVI) to which IP address is assigned on network. https://networkinterview.com/cisco-ftd-deployment-modes/
jcjcjcjcjc 👍 1 Selected: B
Hey moderator, can you explain where you guys got a different answer?
whysohardwhy 👍 1 Selected: B
In routed mode: The BVI acts as the gateway between the bridge group and other routed interfaces. To route between bridge groups/routed interfaces, you must name the BVI. For some interface-based features, you can use the BVI itself https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Cisco Secure Firewall Threat Defense, a Bridge Virtual Interface (BVI) can be utilized in both routed and transparent firewall modes. However, a key distinction is that in transparent mode, the BVI is strictly used for management and cannot be given a name (nameif). In routed mode, the BVI acts as a gateway to route traffic between the bridge group and other routed interfaces, which requires the BVI to be named. Therefore, the presence of a named BVI indicates routed mode.

Why the Other Options Are Wrong

Transparent mode (C) is incorrect because while BVIs are used in transparent mode for management IP addressing, they cannot be named in this mode. IPS only (A) and in-line (D) are incorrect because they do not describe the firewall's routing behavior regarding BVI naming conventions; they refer to deployment types or inspection modes rather than the fundamental firewall mode dictating BVI naming.

Community Comment Notes

Commenters were split between routed and transparent modes. One commenter noted that transparent mode uses bridge groups and BVIs, missing the "named" constraint. Another commenter provided the critical distinction, stating "To route between bridge groups/routed interfaces, you must name the BVI", which correctly identifies why the BVI being named mandates routed mode.

Official Reference

Exam Strategy

Pay close attention to specific adjectives in exam questions, such as "named" or "routed". In FTD, transparent mode BVIs cannot be named, so any mention of a named BVI immediately points to routed mode.

Related Analysis

← Back to 300-710 Study Guide