Which two features are available only in next-generation firewalls? (Choose two.)
A.
Packet filtering
B.
Deep packet inspection
C.
Stateful inspection
D.
Application awareness
E.
Virtual private network
The Answer Is:
B, D
This question includes an explanation.
Explanation:
Next-generation firewalls extend traditional firewall behavior by adding deeper traffic inspection and application-level intelligence. Packet filtering, stateful inspection, and VPN support existed before NGFWs and are not unique to them. Traditional firewalls can permit or deny traffic based on source IP, destination IP, protocol, port, and connection state. NGFWs add the ability to inspect application payloads more deeply, identify applications even when they use nonstandard ports, apply policy based on application identity, detect threats inside permitted sessions, and integrate IPS or malware inspection. Therefore, deep packet inspection and application awareness are the best answers. Deep packet inspection allows the firewall to examine packet contents beyond simple Layer 3 and Layer 4 headers. Application awareness allows policy to distinguish, for example, legitimate HTTPS business traffic from risky file-sharing, tunneling, or unauthorized application traffic over the same port. VPN is useful but not unique to NGFWs. Stateful inspection is also a core feature of earlier stateful firewalls. References/topics: ENCOR Security, next-generation firewall, application visibility, deep packet inspection, IPS, advanced threat protection.
350-401 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"