Chapter 9 Flashcards

firewalls + intrusion prevention system

1
Q

firewall

A

inserted between premise network + internet to establish controlled link
- perimeter defence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

design goal of firewalle

A
  1. all traffic must pass through firewall
  2. only authorized traffic as defined by policy allowed to pass
  3. firewall immune to penetration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

firewall access policy

A

list of types traffic authorized - address range , protocols , applications, content types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Firewall filter characteristics

A
  1. IP address + protocol values - packet filter - limit access to specific service
  2. application protocol - application level gateway - relay + monitor exchange of info for specific application protocols
  3. user identity - for inside users - use form of secure authentication
  4. network activity - control access based on time of request, rate of request , activity patterns
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

firewall capabilities

A
  1. single choke point
  2. location for monitoring security events
  3. platform for several internet function that are not security related
  4. provide platform for IPSec
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

firewall limitations

A
  1. cannot protect against inside attack
  2. cannot protect against attack bypassing firewall
  3. improperly secured WLAN can be accessed from outside
  4. BYOD
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

packet filtering firewall

A
  1. apply rule to incoming + outgoing traffic
  2. rules based on matches in IP/TCP header
  3. info in network packet - source IP , destination IP, source + destination port address , IP protocol field, interface
  4. default policies -discard (prohibit by default) , forward (permit by default)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

advantages of packet filtering firewall

A
  1. simplicity
  2. transparent to users
  3. fast
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

weaknesses of packet filtering

A
  1. cannot prevent attacks that employ application specific vulnerabilities
  2. limited logging functionality
  3. does not support advanced user authentication
  4. vulnerable to TCP/IP spoofing
  5. improper configuration can lead to breaches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

stateful inspection firewall

A
  1. create directory of outbound TCP connections
    2.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly