nerdexam
ExamsCAS-003Questions#327
CompTIA

CAS-003 · Question #327

CAS-003 Question #327: Real Exam Question with Answer & Explanation

The correct answer is D: Vendor A for all remote sites. Standardizing on a single vendor for all 52 remote sites satisfies the CIO's requirements for easy management and capacity for growth by eliminating multi-vendor complexity and providing a consistent, scalable platform.

Question

Following a merger, the number of remote sites for a company has doubled to 52. The company has decided to secure each remote site with an NGFW to provide web filtering, NIDS/NIPS, and network antivirus. The Chief Information Officer (CIO) has requested that the security engineer provide recommendations on sizing for the firewall with the requirements that it be easy to manage and provide capacity for growth. The tables below provide information on a subset of remote sites and the firewall options: Which of the following would be the BEST option to recommend to the CIO?

Exhibits

CAS-003 question #327 exhibit 1
CAS-003 question #327 exhibit 2

Options

  • AVendor C for small remote sites, and Vendor B for large sites.
  • BVendor B for all remote sites
  • CVendor C for all remote sites
  • DVendor A for all remote sites
  • EVendor D for all remote sites

Explanation

Standardizing on a single vendor for all 52 remote sites satisfies the CIO's requirements for easy management and capacity for growth by eliminating multi-vendor complexity and providing a consistent, scalable platform.

Common mistakes.

  • A. Splitting between Vendor C for small sites and Vendor B for large sites introduces a multi-vendor environment requiring separate management consoles, skill sets, and support contracts, which contradicts the CIO's requirement for easy management.
  • B. Vendor B for all sites may be under-provisioned or lack the throughput and features required by larger remote sites based on the site profile data in the reference tables, making it insufficient for capacity at scale.
  • C. Vendor C for all sites is likely sized for smaller deployments and would be inadequate for larger remote sites in terms of throughput and concurrent session capacity as indicated by the comparison tables.
  • E. Vendor D for all sites would likely represent significant over-provisioning at smaller sites, driving unnecessary cost without meeting the balanced sizing and growth capacity requirement specified by the CIO.

Concept tested. NGFW vendor selection for unified management and scalable growth

Reference. https://www.cisco.com/c/en/us/products/security/firewalls/what-is-a-next-generation-firewall.html

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice