nerdexam
CompTIA

SK0-004 · Question #910

An administrator needs three distinct security zones in a company's network. Which of the following is the administrator MOST likely to implement?

The correct answer is B. A Layer 3 firewall. A Layer 3 firewall is the most appropriate solution for creating multiple distinct security zones because it segments and controls traffic between networks at the routing level.

Security and disaster recovery

Question

An administrator needs three distinct security zones in a company's network. Which of the following is the administrator MOST likely to implement?

Options

  • AHost-based firewalls
  • BA Layer 3 firewall
  • CA web application firewall
  • DA circuit-based firewall

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    71% (25)
  • C
    14% (5)
  • D
    9% (3)

Why each option

A Layer 3 firewall is the most appropriate solution for creating multiple distinct security zones because it segments and controls traffic between networks at the routing level.

AHost-based firewalls

Host-based firewalls protect individual endpoints rather than creating network-wide security zones, so they cannot segment traffic between different parts of the infrastructure.

BA Layer 3 firewallCorrect

A Layer 3 firewall operates at the network layer and uses multiple interfaces or subinterfaces to define separate security zones such as a DMZ, internal LAN, and untrusted external network. It enforces access control policies between zones through stateful packet inspection and ACLs applied per interface, making it purpose-built for multi-zone network segmentation. This architecture directly satisfies the requirement for three distinct security zones with controlled traffic flow between them.

CA web application firewall

A web application firewall inspects HTTP/HTTPS application-layer traffic to protect web applications and does not provide the network-level zone segmentation needed for distinct security zones.

DA circuit-based firewall

A circuit-level gateway operates at the session layer to monitor TCP handshakes but is not designed to segment a network into multiple distinct security zones with separate inter-zone policies.

Concept tested: Layer 3 firewall network security zone segmentation

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/general/asa-914-general-config/intro-fw.html

Topics

#network segmentation#Layer 3 firewall#security zones#network security

Community Discussion

No community discussion yet for this question.

Full SK0-004 Practice