nerdexam
Cisco

400-007 · Question #468

Refer to the exhibit. An enterprise underwent a DoS attack sourced from the Internet on their web servers. Their existing firewall failed to handle the attack resulting in services being unavailable…

The correct answer is B. Acquire a firewall from a different vendor and deploy as back-end firewalls. Using firewalls from different vendors in a layered design (defense in depth) avoids a single point of failure due to vendor-specific vulnerabilities or limitations. This ensures higher resilience and stronger protection against future DoS attacks compared to relying on the…

Designing Security

Question

Refer to the exhibit. An enterprise underwent a DoS attack sourced from the Internet on their web servers. Their existing firewall failed to handle the attack resulting in services being unavailable for several hours. The enterprise has decided to add a second firewall layer that will act as a back-end firewall. Both sets of firewalls will be set up to handle DoS attacks, so an identical situation is unlikely to happen again in the future. The current firewall hardware supports virtualization, meaning the same physical hardware can be used as both front-end and back-end firewall. What provides an optimal solution to ensure highest level of security?

Exhibit

400-007 question #468 exhibit

Options

  • AProcure an identical set of physical firewalls and deploy as back-end firewalls.
  • BAcquire a firewall from a different vendor and deploy as back-end firewalls.
  • CDeploy separate logical firewalls from different vendors as front-end and back-end firewalls.
  • DUse a single firewall as both front-end and back-end firewalls through virtualization.

How the community answered

(60 responses)
  • A
    5% (3)
  • B
    85% (51)
  • C
    2% (1)
  • D
    8% (5)

Explanation

Using firewalls from different vendors in a layered design (defense in depth) avoids a single point of failure due to vendor-specific vulnerabilities or limitations. This ensures higher resilience and stronger protection against future DoS attacks compared to relying on the same hardware or virtualized instances of one vendor’s firewall.

Topics

#defense in depth#firewall design#multi-vendor security#DoS protection

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice