nerdexam
CompTIA

CAS-003 · Question #199

An Association is preparing to upgrade their firewalls at five locations around the United States. Each of the three vendor's RFP responses is in-line with the security and other requirements. Which…

The correct answer is B. Create a lab environment to evaluate each of the three firewall platforms. When three vendors all meet the stated RFP requirements on paper, the only reliable way to determine which firewall platform is truly appropriate for the organization is hands-on evaluation in a controlled lab environment. RFP responses describe capabilities claimed by the…

Enterprise Security Architecture

Question

An Association is preparing to upgrade their firewalls at five locations around the United States. Each of the three vendor's RFP responses is in-line with the security and other requirements. Which of the following should the security administrator do to ensure the firewall platform is appropriate for the Association?

Options

  • ACorrelate current industry research with the RFP responses to ensure validity.
  • BCreate a lab environment to evaluate each of the three firewall platforms.
  • CBenchmark each firewall platform's capabilities and experiences with similar sized companies.
  • DDevelop criteria and rate each firewall platform based on information in the RFP responses.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    78% (39)
  • C
    12% (6)
  • D
    4% (2)

Explanation

When three vendors all meet the stated RFP requirements on paper, the only reliable way to determine which firewall platform is truly appropriate for the organization is hands-on evaluation in a controlled lab environment. RFP responses describe capabilities claimed by the vendor, not actual behavior under real conditions. Option A (correlating industry research) is useful background but does not test the product in your specific environment. Option C (benchmarking with similar companies) provides anecdotal data but not direct validation. Option D (rating based on RFP responses) is purely theoretical and does not verify that claimed features work as described. A lab environment lets the security team test each platform against the organization's actual use cases, policies, and traffic patterns before committing to a five-location deployment.

Topics

#firewall evaluation#vendor selection#lab testing#RFP analysis

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice