Changing FTD from Routed to Transparent Mode

Answer Correct answer: A — Deregister the firewall in Cisco Secure Firewall Management Center before changing the mode.

A network administrator manages a network with multiple firewalls in a data center. The administrator must change a next-generation firewall from routed to transparent mode. Which action must the administrator take to meet the requirement?

  1. Deregister the firewall in Cisco Secure Firewall Management Center. Correct Answer
  2. Enter the configure firewall transparent command from the CLI.
  3. Manually delete the interface configuration from the CLI.
  4. Create one or more bridge groups from the CLI.

Community Votes

B
57%
A
43%

57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prerequisite steps for changing an FTD firewall mode; the common trap is assuming the CLI command can be run directly on an FMC-managed device.

Changing a Cisco Secure Firewall Threat Defense device from routed to transparent mode requires deregistration from the Management Center before executing the CLI mode change command. This page explains the prerequisite steps for modifying firewall deployment modes.

Choosing B (enter the configure firewall transparent command) because it is the actual mode-changing command, ignoring that it fails if the device is currently registered to the FMC.

Community Discussion (5 comments)

Andy0724 👍 1 Selected: B
Because never mention of management using FMC
jcjcjcjcjc 👍 1 Selected: B
I go with B since it is not specified the use of an FMC.
whysohardwhy 👍 1 Selected: B
messed up wording, but will go with B which does the change.
Silexis 👍 1 Selected: B
The key is in this sentence "The administrator must change a next-generation firewall from routed to transparent". It doesn't say anything that it is managed from a FMC. And then is asking "which action" (and NOT what is the first action) is made to accomplish the task. The action of changing a firewall deployment mode should be done in CLI
artilling 👍 3 Selected: A
Correct Answer: A Step 1. Deregister the Firepower Threat Defense device from the FMC. Step 2. Access the Firepower Threat Defense device CLI, preferably from the console port. Step 3. > configure firewall [routed | transparent] Step 4. Re-register with the FMC https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/transparent_or_routed_firewall_mode_for_firepower_threat_defense.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To change a Firepower Threat Defense (FTD) device from routed to transparent mode, it must first be deregistered from the Secure Firewall Management Center (FMC). If the device is managed by FMC, the CLI command to change the firewall mode will be blocked and fail. Therefore, deregistering the device from FMC is a mandatory prerequisite action to meet the requirement.

Why the Other Options Are Wrong

Option B is incorrect because the configure firewall transparent command cannot be executed on a device that is actively managed by FMC. Option C is incorrect because while interface configurations are affected when switching modes, manually deleting them from the CLI is not the required action to initiate the mode change. Option D is incorrect because creating bridge groups is a configuration step performed after the firewall has successfully been placed into transparent mode, not the action to change the mode itself.

Community Comment Notes

Several learners chose option B, arguing that the question does not explicitly state the firewall is managed by FMC, as noted by jcjcjcjcjc who "go with B since it is not specified the use of an FMC." However, in the context of the 300-710 SNCF exam, devices are inherently managed by FMC, making deregistration mandatory. The commenter artilling correctly outlined the full sequence, emphasizing that "Step 1. Deregister the Firepower Threat Defense device from the FMC" is required before the CLI command can succeed.

Official Reference

Exam Strategy

For questions involving major device configuration changes like firewall mode, always check if the device's management state (e.g., registered to FMC) blocks the action. Remember that FMC-managed devices require deregistration before executing fundamental mode changes via the CLI.

Related Analysis

← Back to 300-710 Study Guide