300-320 · Question #345
A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology…
The correct answer is B. Virtual-context. Virtual contexts (also called security contexts or multi-context mode) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls. Each security context has its own interfaces, routing table, security policies, NAT rules, and…
Question
A customer with a single Cisco Adaptive Security Appliance wants to separate multiple segments of the e-commerce network to allow for different security policies. What firewall technology accommodates these design requirements?
Options
- ARouted mode
- BVirtual-context
- CTransparent mode
- DVirtual private network
- Eprivate VLANs
- Fadmission control
How the community answered
(36 responses)- A3% (1)
- B89% (32)
- C3% (1)
- F6% (2)
Explanation
Virtual contexts (also called security contexts or multi-context mode) allow a single physical Cisco ASA to be logically partitioned into multiple independent virtual firewalls. Each security context has its own interfaces, routing table, security policies, NAT rules, and access control lists - effectively behaving as a completely separate firewall. For an e-commerce network that needs distinct security zones (e.g., DMZ, payment processing, internal servers, management), virtual contexts allow all of this on one physical appliance with fully isolated policies per segment. Routed mode (A) and transparent mode (C) describe how the ASA handles IP routing but do not provide logical separation. VPN (D), private VLANs (E), and admission control (F) do not address multi-tenant firewall segmentation on a single device.
Topics
Community Discussion
No community discussion yet for this question.