nerdexam
Juniper

JN0-1103 · Question #64

You are designing a network in which access between different groups must be tightly restricted. What should you do to accomplish this task?

The correct answer is A. Use a firewall with security policies to control the traffic. A firewall with security policies is the correct tool for tightly restricting access between different network groups (such as VLANs or security zones) because firewalls operate across multiple layers and can enforce granular, stateful policies based on source/destination IP…

WAN, Security, and Management Design Elements

Question

You are designing a network in which access between different groups must be tightly restricted. What should you do to accomplish this task?

Options

  • AUse a firewall with security policies to control the traffic.
  • BUse a switch with Layer 2 ACLs to control the traffic.
  • CUser a router with Layer 3 ACLs to control the traffic.
  • DUse a Web filtering device to control Layer 7 traffic.

How the community answered

(38 responses)
  • A
    84% (32)
  • B
    8% (3)
  • C
    5% (2)
  • D
    3% (1)

Explanation

A firewall with security policies is the correct tool for tightly restricting access between different network groups (such as VLANs or security zones) because firewalls operate across multiple layers and can enforce granular, stateful policies based on source/destination IP, port, protocol, user identity, and application - giving you comprehensive inter-group access control. Option B is wrong because Layer 2 ACLs on a switch only filter traffic within the same broadcast domain and cannot enforce policies between separate network segments. Option C is partially plausible but falls short - a router with Layer 3 ACLs can filter by IP address and port, but lacks stateful inspection, application awareness, and the policy management features needed for "tight" restriction across groups. Option D is wrong because web filtering targets HTTP/HTTPS content filtering for user browsing, not broad inter-group traffic control.

Memory tip: Think "groups need a gatekeeper" - a Firewall is the Full-featured gatekeeper between network zones, while switches, routers, and web filters each only see part of the picture.

Topics

#firewall policies#access control#security design#traffic segmentation

Community Discussion

No community discussion yet for this question.

Full JN0-1103 Practice