Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: A company deploys Cisco Firepower Threat Defense…

A company deploys Cisco Firepower Threat Defense (FTD) in transparent mode. They create an access control rule to allow HTTP traffic from the inside network (10.10.10.0/24) to a web server at 192.168.1.100. The rule is configured with action 'Allow', a source zone 'inside', a destination zone 'outside', and an intrusion policy attached. After deployment, users report they cannot access the web server. The administrator verifies that the web server is reachable from other networks and that the FTD management interface is accessible. The FTD's packet capture shows no traffic matching the rule. The rule is listed first in the access control policy. What is the most likely cause of the problem?

⚠ Common exam trap

Cisco often tests the distinction between routed and transparent mode, specifically that transparent mode uses interface pairs instead of zones, leading candidates to overlook this fundamental difference and incorrectly assume zone-based rules work in all modes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The FTD is in transparent mode, so it does not use zones; the rule should be assigned to an interface pair.

In transparent mode, Cisco Firepower Threat Defense (FTD) operates as a Layer 2 bridge and does not use security zones. Instead, traffic is controlled by interface pairs. The rule configured with source and destination zones will never match traffic because transparent mode bypasses zone-based policy enforcement. The correct approach is to assign the rule to an interface pair (e.g., inside to outside) rather than zones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The intrusion policy is blocking the traffic.

    Why it's wrong here

    An allow rule with intrusion policy will still permit traffic unless specifically blocked; but here traffic is not matching at all.

  • The web server's IP address is not correctly defined in the network object.

    Why it's wrong here

    The scenario implies correct configuration of the object.

  • The rule's action is set to 'Monitor' instead of 'Allow'.

    Why it's wrong here

    The rule action is stated as 'Allow' in the scenario.

  • The FTD is in transparent mode, so it does not use zones; the rule should be assigned to an interface pair.

    Why this is correct

    Transparent mode FTD requires rules to be applied to specific interface pairs, not security zones.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.