Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

A large enterprise is migrating its data center to a hybrid cloud environment. They need to extend their on-premises network security policies to workloads running in public cloud infrastructure, ensuring consistent enforcement and visibility. The solution must support dynamic scaling and integration with existing security orchestration tools. Which architectural approach best achieves these goals?

  1. ADeploying dedicated hardware firewalls in each public cloud VPC/VNet.
  2. BUtilizing cloud-native security groups and Network ACLs in the public cloud.
  3. CImplementing a virtualized Next-Generation Firewall (NGFW) solution managed by a central orchestrator.
  4. DEstablishing IPsec VPN tunnels from on-premises to each cloud subnet and routing all cloud traffic through on-premises firewalls.
Show answer & explanation

Correct answer: C. Implementing a virtualized Next-Generation Firewall (NGFW) solution managed by a central orchestrator.

Implementing virtualized NGFW solutions managed by a central orchestrator allows for consistent policy enforcement across hybrid environments, dynamic scaling in the cloud, and integration with orchestration tools. This approach overcomes the limitations of cloud-native controls or inefficient traffic routing via on-premises devices.

Why the other options are wrong

  • A. Dedicated hardware firewalls are not suitable for dynamic cloud environments and lack the flexibility for policy synchronization.
  • B. Cloud-native security groups and NACLs can enforce policies but often lack advanced threat capabilities and consistent policy management across hybrid environments.
  • D. Routing all cloud traffic back on-premises (hairpinning) creates latency, bottlenecks, and is not scalable or efficient for cloud-native applications.

Virtualized NGFW in Hybrid Cloud

Leveraging virtual instances of Next-Generation Firewalls (NGFWs) deployed within public cloud environments, integrated with on-premises security, and managed by a centralized platform to ensure consistent security policy enforcement and visibility across hybrid cloud deployments.

  • Extends advanced security capabilities (IPS, app control, URL filtering) to cloud workloads.
  • Enables consistent policy enforcement across on-premises and cloud.
  • Supports dynamic scaling and automation in cloud environments.
  • Managed by a central orchestrator for unified control.

Memory trick: To bridge the cloud and on-prem, use smart, virtual guards.

More Visibility and Enforcement questions