Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: Deploys Cisco Secure Firewall (formerly…

An organization deploys Cisco Secure Firewall (formerly Firepower) in a public cloud environment (AWS). They need to inspect traffic between VPCs. What is the recommended deployment model?

⚠ Common exam trap

Cisco often tests the misconception that deploying a firewall in each VPC with VPC peering is sufficient, but the trap is that VPC peering does not support transitive routing, so traffic between two peered VPCs cannot be forced through a firewall in a third VPC without complex and unsupported routing hacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy firewall as a centralized virtual appliance in a transit VPC

In a public cloud environment like AWS, deploying Cisco Secure Firewall as a centralized virtual appliance in a transit VPC is the recommended model because it allows traffic between multiple VPCs to be routed through a single inspection point. This architecture leverages VPC peering or AWS Transit Gateway to funnel inter-VPC traffic to the firewall, ensuring consistent policy enforcement and visibility without requiring per-VPC firewall instances. Centralized inspection simplifies management, reduces costs, and avoids the complexity of distributed firewall deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy firewall as a centralized virtual appliance in a transit VPC

    Why this is correct

    Centralized inspection in a transit VPC provides consistent policy enforcement for inter-VPC traffic.

  • Install firewall software on each EC2 instance

    Why it's wrong here

    Not scalable and introduces performance overhead on each instance.

  • Deploy firewall in each VPC with VPC peering

    Why it's wrong here

    Distributed deployment complicates policy management and does not guarantee centralized inspection.

  • Use AWS Network Firewall instead

    Why it's wrong here

    While possible, the question specifies Cisco Secure Firewall.

About these practice questions

One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.