Chapter 9: Firewalls and Intrusion Detection Flashcards
When it comes to defense against attacks, one of the most important principles is what?
A. Authorization
B. Authentication
C. Defense-in-Depth
D. Time
Answer: C
Source: Defense-in-Depth Lecture
Firewalls are typically what type of mechanism?
A. Prevention
B. Botnet
C. Attack
D. None of the Above
Answer: A
Source: Defense-in-Depth Lecture
(T/F) The firewall will enforce different security restrictions on traffic
Answer: True
Source: What is a Firewall
A ______ is a device that provides secure connectivity between networks
A. Enterprise Intranet
B. Trusted Users
C. Firewall
D. DMZ
Answer: C
Source: What is a Firewall
Firewalls as a prevention mechanism should be designed to enforce what?
A. User Safety
B. Security Policy
C. Organizational Policy
D. Public Key Infrastructure
Answer: B
Source: Firewall
(T/F) All traffic from internal network to the internet and vice versa (external and out of network) must pass through the firewall
Answer: True
The critical component of planning and implementation of a firewall is specifying a suitable _______ policy
A. Security
B. Access
C. Network
D. Directory
Answer: B
Source: Firewall Access Policy
At a high level the types of traffic that are allowed through the access policy is what?
A. Address Ranges (machines, protocols, applications, and content)
B. IPSEC & TLS
C. Intranet
D. Defense in Depth
Answer: A
Source: Firewall Access Policy
(T/F) A policy should not be developed based on the security and risk assessment/organizational needs but how the CEO thinks it should be
Answer: False
It should be based on what the whole organization needs
(T/F) Firewalls always provide protection 100% of the time
Answer: False
No firewall is 100% secure
(T/F) Firewalls can log all traffic and can provide Network Address Translation
Answer: True
What is firewall filtering?
A. Is when policies are defined for a firewall
B. When firewalls authenticate users into the system
C. When firewalls decide whether to let traffic in or not
D. When firewalls decide to allow for defense in depth strategy
Answer: C
(T/F) Packet filtering at a very high level is essentially a policy that has a set of access control lists based on packet types
Answer: True
Session filtering is based on the context within a session. In order to do this a firewall maintains a session or connection and performs a ________
A. Traffic Block
B. Stateful Inspection
C. DMZ Re-Route
D. Virtual Switch
Answer: B
(T/F) In a packet filtering firewall, decisions are made on a per-packet basis and not other packets
Answer: True