Firewalls (ch 9) Flashcards
What are the mechanisms for Defense-in-Depth?
Prevent, Detect, Survive
What is a firewall?
Provides secure connectivity between networks.
The firewall may be a single computer system or a set of two or more systems that cooperate to perform the firewall function.
True
A firewall can serve as the platform for IPSec.
True
A packet filtering firewall is typically configured to filter packets going in both directions.
True
A prime disadvantage of an application-level gateway is the additional processing overhead on each connection.
True
A DMZ is one of the internal firewalls protecting the bulk of the enterprise network.
False
The _______ defines the transport protocol.
A. destination IP address
B. source IP address
C. interface
D. IP protocol field
D
A _________ gateway sets up two TCP connections, one between itself and a TCP user on an inner host and one between itself and a TCP user on an outside host.
A. packet filtering
B. stateful inspection
C. application-level
D. circuit-level
D
Typically the systems in the ________ require or foster external connectivity such as a corporate Web site, an e-mail server, or a DNS server.
A. DMZ
B. IP protocol field
C. boundary firewall
D. VPN
A
A _______ configuration involves stand-alone firewall devices plus host-based firewalls working together under a central administrative control.
A. packet filtering firewall
B. distributed firewall
C. personal firewall
D. stateful inspection firewall
B
The ________ attack is designed to circumvent filtering rules that depend on TCP header information.
A. tiny fragment
B. address spoofing
C. source routing
D. bastion host
A
Firewalls can stop (select all that Apply):
A. Hackers breaking into your system.
B. Internet Traffic that appears to be from a legitimate source.
C. Viruses and worms that spread through the internet
D. Spyware being put on your system.
E. Viruses and worms that are spread through email.
A, C
A packet filtering firewall is typically configured to filter packets going in both directions.
True
A prime disadvantage of an application-level gateway is the additional processing overhead on each connection.
True