A network architect must provide reliable internet access for business-critical applications while maintaining security controls. Which topology provides both resilience and inspection of all internet-bound traffic?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an active-active firewall cluster with dual ISPs ensures all internet traffic is inspected by stateful firewalls while providing redundancy; if one ISP or firewall fails, traffic continues through the surviving path. A is wrong because LACP aggregation without a firewall provides bandwidth and redundancy but no security inspection.
Full explanation below image
Full Explanation
B is correct because an active-active firewall cluster with dual ISPs ensures all internet traffic is inspected by stateful firewalls while providing redundancy; if one ISP or firewall fails, traffic continues through the surviving path. A is wrong because LACP aggregation without a firewall provides bandwidth and redundancy but no security inspection. C is wrong because round-robin DNS provides load distribution without security inspection and does not enforce traffic policy. D is wrong because MPLS bypass eliminates security inspection, and MPLS is a private WAN service, not an internet access solution.