CAS-003 · Question #467
A company has decided to replace all the T-1 uplinks at each regional office and move away from using the existing MPLS network. All regional sites will use high-speed connections and VPNs to…
The correct answer is D. Firewall. When an organization transitions from a private MPLS network to VPN-based connectivity over the public internet, each regional site requires a firewall to terminate VPN tunnels, enforce security policies, and protect the local network from internet-based threats. Firewalls…
Question
A company has decided to replace all the T-1 uplinks at each regional office and move away from using the existing MPLS network. All regional sites will use high-speed connections and VPNs to connect back to the main campus. Which of the following devices would MOST likely be added at each location?
Options
- ASIEM
- BIDS/IPS
- CProxy server
- DFirewall
- ERouter
How the community answered
(28 responses)- A4% (1)
- C4% (1)
- D89% (25)
- E4% (1)
Explanation
When an organization transitions from a private MPLS network to VPN-based connectivity over the public internet, each regional site requires a firewall to terminate VPN tunnels, enforce security policies, and protect the local network from internet-based threats. Firewalls handle VPN endpoint functionality (IPSec/SSL), packet filtering, and NAT - all essential at each branch site. A SIEM (A) is a centralized log management/analytics tool, not a per-site connectivity device. An IDS/IPS (B) inspects traffic but does not establish VPN tunnels. A proxy server (C) handles web traffic forwarding, not VPN termination. A router (E) can route traffic but does not provide the VPN endpoint and security inspection capabilities needed in this scenario - the firewall is the primary device deployed.
Topics
Community Discussion
No community discussion yet for this question.