CCNP Security 300-710 SNCF Practice Test 2

CCNP Security 300-710 SNCF Practice Test 2 (Hard) - NGIPS Passive and Inline Deployment Modes

CISCO CCNP Security Exam Logo

1 / 10

Which NGIPS deployment mode connects the sensor to a SPAN or mirror port so it can monitor a copy of traffic without being able to directly block malicious packets in real time?

2 / 10

Which NGIPS deployment mode places the sensor directly in the physical traffic path, allowing it to actively drop malicious packets in real time?

3 / 10

Which inline deployment variant allows the NGIPS sensor to be physically in the traffic path while still behaving like a passive sensor for monitoring purposes, useful during initial tuning before enabling blocking?

4 / 10

Which risk is specifically introduced by deploying an NGIPS sensor inline, that does not apply to a passive SPAN-based deployment?

5 / 10

Which interface type must typically be configured for a pair of interfaces to jointly form an inline set on Secure Firewall Threat Defense, allowing traffic to flow through the sensor between them?

6 / 10

Which inline deployment feature allows traffic to continue flowing through an inline pair even if the Secure Firewall Threat Defense device loses power or fails, preventing a full network outage?

7 / 10

Which factor would most directly influence a decision to deploy NGIPS in passive mode rather than inline mode for an initial proof-of-concept evaluation?

8 / 10

Which NGIPS deployment characteristic distinguishes a network tap-based passive deployment from a SPAN-port-based passive deployment?

9 / 10

Which combination of deployment considerations would be most appropriate when planning to move an NGIPS sensor from passive evaluation to full inline production blocking?

10 / 10

Which statement accurately describes how an inline pair interacts with Spanning Tree Protocol (STP) on the surrounding switches when deployed in a Layer 2 environment?

Your score is

The average score is 0%

0%