CAS-002 · Question #195
A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The…
The correct answer is D. Provide each department with a virtual firewall and assign appropriate levels of management. Virtual firewalls provide isolated security boundaries per department on shared physical hardware, reducing datacenter footprint while preserving departmental autonomy.
Question
A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The corporation's Information Security Officer (ISO) is responsible for providing firewall services to both departments, but does not want to increase the hardware footprint within the datacenter. Which of the following should the ISO consider to provide the independent functionality required by each department's IT teams?
Options
- APut both departments behind the firewall and assign administrative control for each
- BProvide each department with a virtual firewall and assign administrative control to the
- CPut both departments behind the firewall and incorporate restrictive controls on each
- DProvide each department with a virtual firewall and assign appropriate levels of management
How the community answered
(25 responses)- A16% (4)
- B4% (1)
- C8% (2)
- D72% (18)
Why each option
Virtual firewalls provide isolated security boundaries per department on shared physical hardware, reducing datacenter footprint while preserving departmental autonomy.
Assigning administrative control over segments of a single non-virtualized physical firewall does not provide true independent security boundary control, as changes to shared objects can affect both departments.
Granting full 'administrative control' to each department over their virtual firewall removes the ISO's ability to enforce corporate-wide security policies, creating a governance problem.
Placing both departments behind one shared firewall with restrictive controls does not give either department independent control of their own security boundary as required.
Virtual firewalls (security contexts or virtual domains) allow a single physical appliance to host multiple independent firewall instances, eliminating additional hardware while granting each department appropriate management control - the qualifier 'appropriate levels' preserves the ISO's overarching policy authority while enabling each department to manage its own security boundary.
Concept tested: Virtual firewall deployment for multi-tenant network isolation
Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.