Firewalls Flashcards

1
Q

What is a firewall?

A

A combination of hardware and
software components that controls the flow of
traffic from one network to another

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where is a firewall normally placed?

A

In between a internal office network and an external public network such as the Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a firewall normally used for?

A
  • Used to protect an internal
    network from the Internet
  • A firewall can also filter traffic
    between any two networks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does a firewall work?

A

-All traffic must pass through the firewall
– Traffic can be restricted in almost any way
– This is more efficient than filtering traffic on each
client in the network
-Firewalls can be used to enforce security policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is a firewall a logical place to log network activity?

A
All traffic passes through the firewall so it is the
logical place to capture information about
network use (and abuse)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do firewalls limit security exposure?

A

– Firewalls are the single point of contact between
the internal and external networks
– People on external networks can only see
computers and services approved by
administrators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does a firewall not do?

A
  • Can’t protect from malicious insiders
    -A firewall can’t protect against traffic that doesn’t go
    through it
    -Firewalls can’t protect against completely new threats
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Depending on the architecture, what 2 or 3 tasks will a firewall perform?

A

– Packet filtering
– Proxying
– Application layer filtering (e.g. anti-virus and antispam filtering)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is packet filtering?

A

The process of examining incoming and outgoing packets to determine which are allowed to pass, and which will be blocked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is proxying?

A

Use of an intermediary service to carry out authorized tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the three most common firewall architectures

A

– Dual homed host
– Screened host
– Screened subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is dual homed host?

A

A dual homed host is a computer with two network connections (two home addresses)
– One IP address for network connection to the
internal network
– One IP address for network connection to the
external network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does dual homed host work?

A
  • Computers on the internal network that want to send traffic to external network send it to the dual homed host.
  • Dual homed host can then perform packet filtering before forwarding traffic
  • Dual homed host performs NAT on internal network IP addresses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a flaw with dual homed host?

A

-Dual homed host is on both networks
- Dual homed host is a single point of failure - there
is no depth of defence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does a screen host work?

A
  • The services of the external network are provided by a host on the internal network by proxying
  • Routing is performed separately by a dedicated routing device such as a router
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What can a router on a screen host allow to happen?

A

Allow other devices other than the firewall screen host connect to certain sites such as accounting site.

17
Q

Why is a screen host generally more secure than a dual homed host?

A

Because the primary point of contact with the external network is a router not a host, and routers tend to be more difficult to compromise than hosts

18
Q

How does a screened subnet work?

A

The firewall host is place between an internal router and an external router