chapter 9 Flashcards
The firewall may be a single computer system or a set of two or more
systems that cooperate to perform the firewall function.
T
A firewall can serve as the platform for IPSec.
T
The firewall can protect against attacks that bypass the firewall
F
A packet filtering firewall is typically configured to filter packets going
in both directions.
T
One disadvantage of a packet filtering firewall is its simplicity
F
The countermeasure to tiny fragment attacks is to discard packets with
an inside source address if the packet arrives on an external interface.
F
A traditional packet filter makes filtering decisions on an individual
packet basis and does not take into consideration any higher layer context.
T
A prime disadvantage of an application-level gateway is the additional
processing overhead on each connection.
T
The primary role of the personal firewall is to deny unauthorized
remote access to the computer.
T
A DMZ is one of the internal firewalls protecting the bulk of the
enterprise network
F
A logical means of implementing an IPSec is in a firewall.
T
Distributed firewalls protect against internal attacks and provide
protection tailored to specific machines and applications.
T
An important aspect of a distributed firewall configuration is security
monitoring.
T
Unlike a firewall, an IPS does not block traffic.
F
Snort Inline enables Snort to function as an intrusion prevention
capability.
T