1-2-2 Flashcards

1
Q

In which firewall mode does Cisco Secure Firewall operate without IP addresses on its interfaces?

A

Transparent mode.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two firewall modes available in Cisco Secure Firewall?

A

Transparent and Routed modes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What advantage does routed mode have over transparent mode in Cisco Secure Firewall?

A

It supports advanced services like routing, DHCP, and VPN functionalities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain a practical scenario where transparent mode is preferable.

A

When firewall protection is required without changing the existing network addressing scheme.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the primary functional difference between inline interfaces and inline tap interfaces?

A

Inline interfaces actively block malicious traffic, while inline tap interfaces only detect and monitor copied traffic without blocking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When would it be beneficial to deploy passive mode interfaces in your network? Provide an example scenario.

A

For intrusion detection purposes without affecting actual traffic flow, such as monitoring mirrored traffic for policy tuning or compliance verification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does clustering differ from failover pair deployments in Cisco Secure Firewall? Provide one advantage.

A

Clustering groups multiple firewalls actively handling traffic simultaneously, increasing throughput and availability, whereas failover pairs have one active and one standby firewall. Advantage: Enhanced scalability alongside high availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What scenario might justify using the fail-to-wire option with inline interfaces?

A

Ensuring business continuity by allowing traffic flow during firewall outages, power failures, or software upgrades.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly