Changing FTD from Routed to Transparent Mode
A network administrator manages a network with multiple firewalls in a data center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take to meet the requirement?
Community Votes
57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prerequisite steps for changing an FTD firewall mode; the common trap is assuming the CLI command can be run directly on an FMC-managed device.
Changing a Cisco Secure Firewall Threat Defense device from routed to transparent mode requires deregistration from the Management Center before executing the CLI mode change command. This page explains the prerequisite steps for modifying firewall deployment modes.
Choosing B (enter the configure firewall transparent command) because it is the actual mode-changing command, ignoring that it fails if the device is currently registered to the FMC.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To change a Firepower Threat Defense (FTD) device from routed to transparent mode, it must first be deregistered from the Secure Firewall Management Center (FMC). If the device is managed by FMC, the CLI command to change the firewall mode will be blocked and fail. Therefore, deregistering the device from FMC is a mandatory prerequisite action to meet the requirement.Why the Other Options Are Wrong
Option B is incorrect because theconfigure firewall transparent command cannot be executed on a device that is actively managed by FMC. Option C is incorrect because while interface configurations are affected when switching modes, manually deleting them from the CLI is not the required action to initiate the mode change. Option D is incorrect because creating bridge groups is a configuration step performed after the firewall has successfully been placed into transparent mode, not the action to change the mode itself.Community Comment Notes
Several learners chose option B, arguing that the question does not explicitly state the firewall is managed by FMC, as noted by jcjcjcjcjc who "go with B since it is not specified the use of an FMC." However, in the context of the 300-710 SNCF exam, devices are inherently managed by FMC, making deregistration mandatory. The commenter artilling correctly outlined the full sequence, emphasizing that "Step 1. Deregister the Firepower Threat Defense device from the FMC" is required before the CLI command can succeed.Official Reference
Exam Strategy
For questions involving major device configuration changes like firewall mode, always check if the device's management state (e.g., registered to FMC) blocks the action. Remember that FMC-managed devices require deregistration before executing fundamental mode changes via the CLI.