nerdexam
CompTIA

CAS-001 · Question #152

A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The…

The correct answer is D. Provide each department with a virtual firewall and assign appropriate levels of management for. Virtual firewalls (also called virtual firewall instances or contexts, available on platforms like Cisco ASA or Palo Alto) allow a single physical firewall appliance to operate as multiple independent logical firewalls. Each virtual instance has its own routing, policies, and…

Technical Integration of Enterprise Components

Question

A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The corporation's Information Security Officer (ISO) is responsible for providing firewall services to both departments, but does not want to increase the hardware footprint within the datacenter. Which of the following should the ISO consider to provide the independent functionality required by each department's IT teams?

Options

  • APut both departments behind the firewall and assign administrative control for each department
  • BProvide each department with a virtual firewall and assign administrative control to the physical
  • CPut both departments behind the firewall and incorporate restrictive controls on each department's
  • DProvide each department with a virtual firewall and assign appropriate levels of management for

How the community answered

(25 responses)
  • A
    16% (4)
  • B
    4% (1)
  • C
    4% (1)
  • D
    76% (19)

Explanation

Virtual firewalls (also called virtual firewall instances or contexts, available on platforms like Cisco ASA or Palo Alto) allow a single physical firewall appliance to operate as multiple independent logical firewalls. Each virtual instance has its own routing, policies, and administrative domain. Option D is correct because it provides each department with its own virtual firewall AND assigns appropriate management levels - meaning each department's IT team gets administrative control over their own virtual firewall boundary without accessing the other department's firewall or the underlying physical hardware. This satisfies both requirements: independent security boundary control per department and no additional hardware. Options A and C place both departments behind a shared firewall without independent control, which does not meet the requirement. Option B partially addresses it but assigns control to the physical layer, which could give one department's admins access to the shared hardware, undermining independence.

Topics

#virtual firewall#network segmentation#firewall administration#virtualization

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice