CAS-003 · Question #327
Following a merger, the number of remote sites for a company has doubled to 52. The company has decided to secure each remote site with an NGFW to provide web filtering, NIDS/NIPS, and network…
The correct answer is D. Vendor A for all remote sites. Standardizing on a single vendor for all 52 remote sites satisfies the CIO's requirements for easy management and capacity for growth by eliminating multi-vendor complexity and providing a consistent, scalable platform.
Question
Following a merger, the number of remote sites for a company has doubled to 52. The company has decided to secure each remote site with an NGFW to provide web filtering, NIDS/NIPS, and network antivirus. The Chief Information Officer (CIO) has requested that the security engineer provide recommendations on sizing for the firewall with the requirements that it be easy to manage and provide capacity for growth. The tables below provide information on a subset of remote sites and the firewall options:
Which of the following would be the BEST option to recommend to the CIO?
Exhibits
Options
- AVendor C for small remote sites, and Vendor B for large sites.
- BVendor B for all remote sites
- CVendor C for all remote sites
- DVendor A for all remote sites
- EVendor D for all remote sites
How the community answered
(33 responses)- A18% (6)
- B3% (1)
- C9% (3)
- D67% (22)
- E3% (1)
Why each option
Standardizing on a single vendor for all 52 remote sites satisfies the CIO's requirements for easy management and capacity for growth by eliminating multi-vendor complexity and providing a consistent, scalable platform.
Splitting between Vendor C for small sites and Vendor B for large sites introduces a multi-vendor environment requiring separate management consoles, skill sets, and support contracts, which contradicts the CIO's requirement for easy management.
Vendor B for all sites may be under-provisioned or lack the throughput and features required by larger remote sites based on the site profile data in the reference tables, making it insufficient for capacity at scale.
Vendor C for all sites is likely sized for smaller deployments and would be inadequate for larger remote sites in terms of throughput and concurrent session capacity as indicated by the comparison tables.
Vendor A for all remote sites provides a unified NGFW platform across every location, enabling centralized policy management, consistent feature sets (web filtering, NIDS/NIPS, and network antivirus), and a single support relationship - reducing operational complexity and providing a standardized baseline that scales as the organization grows further.
Vendor D for all sites would likely represent significant over-provisioning at smaller sites, driving unnecessary cost without meeting the balanced sizing and growth capacity requirement specified by the CIO.
Concept tested: NGFW vendor selection for unified management and scalable growth
Source: https://www.cisco.com/c/en/us/products/security/firewalls/what-is-a-next-generation-firewall.html
Topics
Community Discussion
No community discussion yet for this question.

