nerdexam
Cisco

300-320 · Question #444

A customer would like to implement a firewall to secure an enterprise network. However, the customer is unable to allocate any new subnets. What type of firewall mode must be implemented?

The correct answer is C. transparent. A transparent mode firewall operates at Layer 2, functioning like a bridge or a 'bump in the wire.' Because it works at Layer 2, it does not require any new IP subnets or routing changes to insert it into an existing network-it is assigned a management IP but does not act as a…

Security Services

Question

A customer would like to implement a firewall to secure an enterprise network. However, the customer is unable to allocate any new subnets. What type of firewall mode must be implemented?

Options

  • Arouted
  • Bactive/standby
  • Ctransparent
  • Dvirtual
  • Eactive/active
  • Fzone based

How the community answered

(40 responses)
  • C
    95% (38)
  • D
    3% (1)
  • F
    3% (1)

Explanation

A transparent mode firewall operates at Layer 2, functioning like a bridge or a 'bump in the wire.' Because it works at Layer 2, it does not require any new IP subnets or routing changes to insert it into an existing network-it is assigned a management IP but does not act as a routed hop for traffic. This is ideal when a customer cannot allocate new subnets. A routed mode firewall (Option A) acts as a Layer 3 hop and requires new subnets on each interface. Active/standby (B) and active/active (E) describe high-availability deployment models, not firewall modes. Virtual (D) refers to virtual firewall contexts. Zone-based (F) is a firewall policy model, not a deployment mode.

Topics

#transparent firewall#ASA modes#firewall design#Layer 2 firewall

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice