350-701 · Question #29
Which ASA deployment mode can provide separation of management on a shared appliance?
The correct answer is C. multiple context mode. Multiple context mode on an ASA allows a single appliance to be logically partitioned, enabling separate management.
Question
Which ASA deployment mode can provide separation of management on a shared appliance?
Options
- ADMZ multiple zone mode
- Btransparent firewall mode
- Cmultiple context mode
- Drouted mode
How the community answered
(40 responses)- A3% (1)
- B3% (1)
- C90% (36)
- D5% (2)
Why each option
Multiple context mode on an ASA allows a single appliance to be logically partitioned, enabling separate management.
DMZ multiple zone mode refers to configuring multiple security zones, including a DMZ, within a single firewall context, not separating management of the appliance itself.
Transparent firewall mode places the ASA logically inline with a network segment without requiring any IP address configuration on the interfaces, but it does not provide management separation for shared appliances.
Cisco ASA multiple context mode allows a single physical ASA appliance to be partitioned into multiple virtual devices, each acting as an independent firewall with its own security policy, interfaces, and management. This provides complete separation of management and configuration for different tenants or departments on a shared appliance.
Routed mode is the default and most common operating mode where the ASA acts as a Layer 3 hop between networks, but it does not inherently offer separation of management for multiple logical firewalls on a single appliance.
Concept tested: Cisco ASA multiple context mode
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/ha_contexts.html
Topics
Community Discussion
No community discussion yet for this question.