nerdexam
Cisco

300-710 · Question #155

Within an organization's high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on

The correct answer is D. multi-instance firewalls. To segment traffic for different departments across an active-active high availability firewall environment, multi-instance firewalls are required. This allows each department's traffic to be processed by a dedicated virtual firewall instance.

Configuration

Question

Within an organization’s high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?

Options

  • Aredundant interfaces
  • Bspan EtherChannel clustering
  • Chigh availability active/standby firewalls
  • Dmulti-instance firewalls

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    15% (4)
  • D
    73% (19)

Why each option

To segment traffic for different departments across an active-active high availability firewall environment, multi-instance firewalls are required. This allows each department's traffic to be processed by a dedicated virtual firewall instance.

Aredundant interfaces

Redundant interfaces provide hardware fault tolerance but do not inherently segment traffic based on departments or enable an active-active processing model.

Bspan EtherChannel clustering

SPAN (Switched Port Analyzer) is for traffic monitoring, and EtherChannel bundles physical links for bandwidth and redundancy; neither directly provides multi-departmental firewall segmentation.

Chigh availability active/standby firewalls

High availability active/standby firewalls mean only one firewall actively passes traffic at a time, which contradicts the requirement that 'both firewalls are passing traffic.'

Dmulti-instance firewallsCorrect

Multi-instance firewalls allow multiple virtual firewall instances to run on a single physical firewall device, each operating independently with its own policies and interfaces. This enables effective traffic segmentation for different departments within an active-active HA setup, where each instance can be dedicated to a specific department's traffic.

Concept tested: Firewall virtualization and multi-instance deployment for segmentation

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/configuration/firewall/asa-913-firewall-config/ha-contexts.html

Topics

#Multi-instance Firewalls#High Availability#Traffic Segmentation#Security Contexts

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice