nerdexam
CompTIA

CAS-002 · Question #195

A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The…

The correct answer is D. Provide each department with a virtual firewall and assign appropriate levels of management. Virtual firewalls provide isolated security boundaries per department on shared physical hardware, reducing datacenter footprint while preserving departmental autonomy.

Technical Integration of Enterprise Components

Question

A corporation has Research and Development (R&D) and IT support teams, each requiring separate networks with independent control of their security boundaries to support department objectives. The corporation's Information Security Officer (ISO) is responsible for providing firewall services to both departments, but does not want to increase the hardware footprint within the datacenter. Which of the following should the ISO consider to provide the independent functionality required by each department's IT teams?

Options

  • APut both departments behind the firewall and assign administrative control for each
  • BProvide each department with a virtual firewall and assign administrative control to the
  • CPut both departments behind the firewall and incorporate restrictive controls on each
  • DProvide each department with a virtual firewall and assign appropriate levels of management

How the community answered

(25 responses)
  • A
    16% (4)
  • B
    4% (1)
  • C
    8% (2)
  • D
    72% (18)

Why each option

Virtual firewalls provide isolated security boundaries per department on shared physical hardware, reducing datacenter footprint while preserving departmental autonomy.

APut both departments behind the firewall and assign administrative control for each

Assigning administrative control over segments of a single non-virtualized physical firewall does not provide true independent security boundary control, as changes to shared objects can affect both departments.

BProvide each department with a virtual firewall and assign administrative control to the

Granting full 'administrative control' to each department over their virtual firewall removes the ISO's ability to enforce corporate-wide security policies, creating a governance problem.

CPut both departments behind the firewall and incorporate restrictive controls on each

Placing both departments behind one shared firewall with restrictive controls does not give either department independent control of their own security boundary as required.

DProvide each department with a virtual firewall and assign appropriate levels of managementCorrect

Virtual firewalls (security contexts or virtual domains) allow a single physical appliance to host multiple independent firewall instances, eliminating additional hardware while granting each department appropriate management control - the qualifier 'appropriate levels' preserves the ISO's overarching policy authority while enabling each department to manage its own security boundary.

Concept tested: Virtual firewall deployment for multi-tenant network isolation

Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final

Topics

#virtual firewall#network segmentation#virtualization#multi-tenant security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice