Which common type of attack does a data center next-generation firewall protect against?
A.
DDoS protection
B.
Unauthorized analyzers
C.
Rogue APs
D.
Malicious or risky applications
The Answer Is:
D
This question includes an explanation.
Explanation:
A next-generation firewall protects against more than basic IP, port, and protocol violations. Its key value is application visibility and control. In a data center, an NGFW can identify applications regardless of port, inspect application behavior, enforce policy based on application identity, and block malicious or risky applications that traditional firewalls may allow if they use permitted ports such as TCP 80 or 443. Therefore, option D is the best answer. DDoS protection is usually handled by dedicated DDoS mitigation systems, upstream scrubbing services, rate limiting, or cloud-based DDoS protection rather than being the defining function of a data center NGFW. Unauthorized analyzers and rogue APs are not the primary threat categories addressed by a data center NGFW; rogue AP detection is more aligned with wireless security and WIPS/WIDS. The key ENCOR concept is that NGFWs add application awareness, user/context-based policy, intrusion prevention, malware inspection, and advanced threat defense to traditional stateful firewalling. References/topics: ENCOR Security, Cisco Threat Defense, next-generation firewall, application control, malware prevention, data center security.
350-401 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"