Firewall Flashcards

1
Q

Give a high level overview of Firewall

A

protects systems, network resources, and applications from external and internal attacks.

Firewall scans all incoming and outgoing traffic and compares it to its list of firewall rules, which is a set of
criteria with associated actions. If a packet matches all criteria in a rule, the firewall acts according to the rule,
blocking or allowing the packet through the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What features make up the “Protect” section of Firewall?

A

Rules, Rule Groups, Stateful Packet Filtering and inspection, Reputation Based Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What features make up the “Detect” section of Firewall?

A

Dashboards and Monitors, Queries and Reports, Alerts, Log Traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What features make up the “Correct” section of Firewall?

A

What features make up the “Correct” section of Firewall?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Give a High Level Explanation of Firewall “Rules”

A

A way to define the criteria Firewall uses to determine whether to block or allow incoming and outgoing traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Give a High Level Explanation of Firewall “Rule Groups”

A

Organize firewall rules for easy management, enabling you to apply rules manually or on a schedule, and to only process traffic based on connection type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Give a High Level Explanation of “Stateful packet filtering and inspection”

A

Track network connection state and characteristics in a state table, allowing only packets that match a known open connection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Give a High Level Explanation of Firewall “Reputation-based control”

A

Block untrusted executables, or all traffic from an untrusted network, based on reputation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Give a High Level Explanation of Adaptive mode

A

Create rules automatically on the client system to allow legitimate activity.
Once created, analyze client rules to decide which to convert to server-mandated policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Give a High Level Explanation of “Defined Networks”

A

Define trusted networks to allow traffic from networks that your organization considers safe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Give a High Level Explanation of “Firewall Catalog”

A

Define rules and groups to add to multiple policies, or networks and applications to add to firewall rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How does Firewall work?

A

It scans all incoming and outgoing traffic at the packet level and compares packets to the configured firewall rules to determine whether to allow or block the traffic

1 The administrator configures firewall rules in McAfee ePO and enforces the policy to the client system.

2 The user performs a task that initiates network activity and generates traffic.

3 Firewall scans all incoming and outgoing traffic and compares packets to configured rules. If the traffic
matches a rule, Firewall blocks or allows it, based on the rule criteria.

4 Firewall logs the details, then generates and sends an event to McAfee ePO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do firewall rules work?

A

-Determine how to handle network traffic
-Each rule provides a set of conditions that traffic must meet, and an action to allow or block traffic
-When firewall finds traffic that matches a rule’s conditions, it performs the associated action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does the order of firewall rules affect the way they’re used?

A

Firewall uses precedence to apply rules:

1 Firewall applies the rule at the top of the firewall rules list. If the traffic meets this rule’s conditions, Firewall allows or blocks the traffic. It doesn’t try to apply any other rules in the list.

2 If the traffic doesn’t meet the first rule’s conditions, Firewall continues to the next rule in the list until it finds
a rule that the traffic matches.

3 If no rule matches, the firewall automatically blocks the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What happens if all of the configured Firewall rules are applied and none match the sample?

A

It’s automatically blocked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What happens if all of the configured Firewall rules are applied and none match the sample, and adaptive mode is active?

A

an Allow rule is created for the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What happens if intercepted traffic matches more than one rule in the list?

A

Firewall applies only the first matching rule in the list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the best practice in regards to rule order?

A

The more specific rules should be placed at the top of the list, and the more general rules at the bottom, which ensures that Firewall filters traffic appropriately

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How do firewall rule groups work?

A

Firewall rule groups organize firewall rules for easy management. They do not affect the way Firewall handles rules; the software processes rules from top to bottom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Does FIrewall prioritize the settings of a rule group first in processing, or the settings for the individual rules it contains?

A

It processes the settings for the group first.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

If a conflict exists between the settings of a firewall group, and the rules it contains, what happens?

A

The group settings take precedence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are Timed Groups?

A

Timed groups are Firewall rule groups that are active for a set time.

For example, a timed group can be enabled to allow a client system to connect to a public network and establish a VPN connection

Groups can be activated either: on a specified schedule, or manually by selecting options from the McAfee system tray icon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What are Connection Isolation Groups?

A
24
Q

What are the predefined firewall rule groups in ePO

A
25
Q

What are the predefined firewall rule groups on the client?

A
26
Q

What are the parameters for allowed connections that can be included after enabling location status and naming the location in a location aware group?

A
27
Q

How does the connection isolation setting work?

A
28
Q

What is stateful packet filtering?

A
29
Q

What is the state table?

A
30
Q

What is stateful packet inspection?

A
31
Q

How does stateful packet filtering work?

A
32
Q

What do entries in a state table base their definitions of connections on?

A
33
Q

If firewall rule sets change, what happens in the state table?

A
34
Q

If an adapter obtains a new IP address, what happens in the state table?

A
35
Q

What happens in the state table when a process ends?

A
36
Q

How does stateful packet inspection work??

A
37
Q

How is UDP protocol handled by Firewall?

A
38
Q

How is ICMPv4/v6 protocol handled by Firewall?

A
39
Q

How is TCP protocol handled by Firewall?

A
40
Q

How is DNS Protocol handled by Firewall?

A
41
Q

How is DHCP Protocol handled by Firewall?

A
42
Q

How do Trusted Networks work

A
43
Q

How do Trusted Executables and Applications work?

A
44
Q

What is the firewall catalog?

A
45
Q

What is the Link Layer?

A
46
Q

What is the Network Layer?

A
47
Q

What is TCP

A
48
Q

What is UDP

A
49
Q

What is ICMP

A
50
Q

How does Firewall handle common unsupported protocols?

A
51
Q

How does McAfee GTI work with Firewall

A
52
Q

What are the reputation levels used with GTI & FireWall?

A
53
Q

Does McAfee GTI introduce latency? How much?

A
54
Q

If Firewall can’t reach the McAfee GTI servers, does traffic stop?

A
55
Q

How does tuning work?

A
56
Q

According to the product guide, for at least how long should you leave Firewall in adaptive mode?

A