Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-745 Exam - Topic 1 Question 7 Discussion

A technology company has many remote workers who access corporate resources from various locations. The company must ensure that security policies are managed and enforced directly on endpoints, and endpoints are protected from threats regardless of location. Which firewall architecture meets the requirements?
B) host-based firewall
A) next-generation firewall
C) web application firewall
D) traditional firewall

Cisco 300-745 Exam - Topic 1 Question 7 Discussion

Actual exam question for Cisco's 300-745 exam
Question #: 7
Topic #: 1
[All 300-745 Questions]

A technology company has many remote workers who access corporate resources from various locations. The company must ensure that security policies are managed and enforced directly on endpoints, and endpoints are protected from threats regardless of location. Which firewall architecture meets the requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B

As organizations shift toward a 'borderless' or hybrid work model, the traditional perimeter-based security model becomes insufficient. When employees work from home, coffee shops, or airports, they are no longer behind the enterprise's physical Next-Generation Firewall (NGFW) (Option A). To ensure that security policies are enforced 'regardless of location,' the security must move with the device.

A host-based firewall is a software-defined firewall that resides directly on the endpoint (laptop, workstation, or server). In the Cisco ecosystem, this is often a component of Cisco Secure Client or Cisco Secure Endpoint. Because the firewall is local to the operating system, it can enforce strict inbound and outbound traffic rules even when the user is not connected to a VPN. This protects the device from lateral movement threats on untrusted local networks (like a public Wi-Fi) and ensures that only authorized applications can communicate over the network.

While an NGFW (Option A) provides superior deep packet inspection for the corporate perimeter, and a Web Application Firewall (WAF) (Option C) protects web servers from application-layer attacks, neither provides the local, location-independent protection required for a distributed remote workforce. Implementing a host-based firewall aligns with the Zero Trust architecture promoted by Cisco, where the endpoint itself becomes a micro-perimeter capable of self-protection.


Contribute your Thoughts:

0/2000 characters
Jennifer
1 month ago
A) next-generation firewall is definitely more comprehensive for remote workers.
upvoted 0 times
...
Minna
2 months ago
I agree, but B) host-based firewall could work too. It protects individual devices.
upvoted 0 times
...
Enola
2 months ago
I think A) next-generation firewall is the best choice. It offers advanced security features.
upvoted 0 times
...
Merrilee
2 months ago
Nah, web application firewalls are for apps, not endpoints.
upvoted 0 times
...
Nickie
2 months ago
Surprised that traditional firewalls are even an option!
upvoted 0 times
...
Ernest
2 months ago
I think a host-based firewall could work too, though.
upvoted 0 times
...
Vilma
4 months ago
Totally agree, it offers advanced threat protection!
upvoted 0 times
...
Alba
4 months ago
A next-generation firewall is the best choice here.
upvoted 0 times
...
Margo
5 months ago
I feel like the traditional firewall wouldn't be sufficient for remote access scenarios, but I can't recall the specifics of why that is.
upvoted 0 times
...
Tomoko
5 months ago
I'm leaning towards the host-based firewall too, but I wonder if the next-generation firewall could also manage policies effectively for remote workers.
upvoted 0 times
...
Marshall
5 months ago
I remember practicing a question similar to this, and I think next-generation firewalls are more about advanced features rather than just endpoint protection.
upvoted 0 times
...
Verda
5 months ago
I think the host-based firewall might be the right choice since it protects individual endpoints directly, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel