nerdexam
Cisco

300-320 · Question #345

A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology…

The correct answer is B. Virtual-context. Virtual contexts (also called security contexts or multi-context mode) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls. Each security context has its own interfaces, routing table, security policies, NAT rules, and…

Security Services

Question

A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology accommodates these design requirements?

Options

  • ARouted mode
  • BVirtual-context
  • CTransparent mode
  • DVirtual private network
  • Eprivate VLANs
  • Fadmission control

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    89% (32)
  • C
    3% (1)
  • F
    6% (2)

Explanation

Virtual contexts (also called security contexts or multi-context mode) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls. Each security context has its own interfaces, routing table, security policies, NAT rules, and access control lists - effectively behaving as a completely separate firewall. For an e-commerce network that needs distinct security zones (e.g., DMZ, payment processing, internal servers, management), virtual contexts allow all of this on one physical appliance with fully isolated policies per segment. Routed mode (A) and transparent mode (C) describe how the ASA handles IP routing but do not provide logical separation. VPN (D), private VLANs (E), and admission control (F) do not address multi-tenant firewall segmentation on a single device.

Topics

#ASA virtual context#multi-context mode#security policy segmentation#firewall

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice