mediumMultiple ChoiceObjective-mapped
350-701 Practice Question: Deploys Cisco Secure Firewall (formerly…
An organization deploys Cisco Secure Firewall (formerly Firepower) in a public cloud environment (AWS). They need to inspect traffic between VPCs. What is the recommended deployment model?
⚠ Common exam trap
Cisco often tests the misconception that deploying a firewall in each VPC with VPC peering is sufficient, but the trap is that VPC peering does not support transitive routing, so traffic between two peered VPCs cannot be forced through a firewall in a third VPC without complex and unsupported routing hacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy firewall as a centralized virtual appliance in a transit VPC
In a public cloud environment like AWS, deploying Cisco Secure Firewall as a centralized virtual appliance in a transit VPC is the recommended model because it allows traffic between multiple VPCs to be routed through a single inspection point. This architecture leverages VPC peering or AWS Transit Gateway to funnel inter-VPC traffic to the firewall, ensuring consistent policy enforcement and visibility without requiring per-VPC firewall instances. Centralized inspection simplifies management, reduces costs, and avoids the complexity of distributed firewall deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy firewall as a centralized virtual appliance in a transit VPC
Why this is correct
Centralized inspection in a transit VPC provides consistent policy enforcement for inter-VPC traffic.
- ✗
Install firewall software on each EC2 instance
Why it's wrong here
Not scalable and introduces performance overhead on each instance.
- ✗
Deploy firewall in each VPC with VPC peering
Why it's wrong here
Distributed deployment complicates policy management and does not guarantee centralized inspection.
- ✗
Use AWS Network Firewall instead
Why it's wrong here
While possible, the question specifies Cisco Secure Firewall.
Go deeper
Related to this question
About these practice questions
One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.