nerdexam
Cisco

300-320 · Question #157

A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology…

The correct answer is A. virtual contexts. Virtual contexts (also called security contexts) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls, each with its own interfaces, routing tables, security policies, NAT rules, and administrator access. This directly solves…

Security Services

Question

A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology accommodates these design requirements?

Options

  • Avirtual contexts
  • Bprivate VLANs
  • Cadmission control
  • Dvirtual private network

How the community answered

(36 responses)
  • A
    86% (31)
  • B
    8% (3)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Virtual contexts (also called security contexts) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls, each with its own interfaces, routing tables, security policies, NAT rules, and administrator access. This directly solves the requirement of separating multiple network segments with different security policies on a single physical device. Private VLANs operate at Layer 2 to isolate hosts within a VLAN but do not provide independent firewall policy enforcement. Admission control and VPNs address different security concerns and do not fulfill the multi-policy segmentation requirement.

Topics

#ASA#virtual contexts#multi-context firewall#security policy segmentation

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice