Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-745 Exam - Topic 2 Question 15 Discussion

After a recent security breach, a financial company is reassessing their overall security posture and strategy to better protect sensitive data and resources. The company already deployed on-premises next-generation firewalls at the network edge for each branch location. Security measures must be enhanced at the endpoint level. The goal is to implement a solution that provides additional traffic filtering directly on endpoint devices, thereby offering another layer of defense against potential threats. Which technology must be implemented to meet the requirement?
A) host-based firewall
B) web application firewall
C) distributed firewall
D) traditional firewall

Cisco 300-745 Exam - Topic 2 Question 15 Discussion

Actual exam question for Cisco's 300-745 exam
Question #: 15
Topic #: 2
[All 300-745 Questions]

After a recent security breach, a financial company is reassessing their overall security posture and strategy to better protect sensitive data and resources. The company already deployed on-premises next-generation firewalls at the network edge for each branch location. Security measures must be enhanced at the endpoint level. The goal is to implement a solution that provides additional traffic filtering directly on endpoint devices, thereby offering another layer of defense against potential threats. Which technology must be implemented to meet the requirement?

Show Suggested Answer Hide Answer
Suggested Answer: A

When moving security closer to the data, the endpoint becomes the final perimeter. A host-based firewall is a software component that runs directly on the endpoint's operating system (Windows, macOS, or Linux). While the company already has Next-Generation Firewalls (NGFWs) at the network edge, those devices cannot protect endpoints from threats originating within the same local network segment (East-West traffic) or when the device is used outside the corporate office.

Implementing a host-based firewall provides a critical layer of defense-in-depth. It allows security administrators to enforce strict inbound and outbound traffic rules based on applications and services specific to that device. For example, it can prevent a compromised laptop from scanning other devices on a public Wi-Fi network. In the Cisco ecosystem, this is often achieved through the Cisco Secure Client (AnyConnect) using the Network Visibility Module (NVM) or integrated endpoint security suites.

While a Distributed Firewall (Option C) is used for micro-segmentation within data centers/clouds and a Web Application Firewall (WAF) (Option B) protects servers from web-based attacks, only a host-based firewall meets the requirement for traffic filtering directly on the diverse array of endpoint devices. This approach ensures that even if the network edge is bypassed, the individual host remains hardened against lateral movement and unauthorized communication.


Contribute your Thoughts:

0/2000 characters
Wilbert
4 days ago
A host-based firewall is definitely the way to go for endpoint protection.
upvoted 0 times
...
Lindsey
9 days ago
I’m confused; I thought traditional firewalls were enough, but maybe they don’t offer the endpoint protection needed here?
upvoted 0 times
...
Tamesha
14 days ago
I practiced a similar question, and I believe A) host-based firewall is the best choice for adding that extra layer at the endpoint.
upvoted 0 times
...
Truman
19 days ago
I'm not entirely sure, but I remember something about distributed firewalls being useful for endpoint security too.
upvoted 0 times
...
Sophia
24 days ago
I think the answer might be A) host-based firewall since it provides filtering directly on the endpoint devices.
upvoted 0 times
...

Save Cancel