Lecture 10 Pt. 4 Flashcards

1
Q

What does NGFW stand for?

A

Next Generation Firewall

NGFW provides advanced security features beyond traditional firewalls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary purpose of Threat Prevention in NGFW?

A

To challenge today’s threat landscape using a multi-layered defense approach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name two vendors that offer NGFW solutions.

A
  • Palo Alto
  • Checkpoint
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What integrated service does Palo Alto’s NGFW provide?

A

Integrated threat prevention services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What key feature does Palo Alto’s WildFire provide?

A

Cloud-based malware analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: Palo Alto’s threat prevention relies solely on predefined ports.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What technology does Palo Alto use to identify and add context to all traffic?

A
  • User-ID
  • App-ID
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of attacks does Palo Alto Networks Advanced Threat Prevention aim to stop?

A

Zero-day attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the function of Palo Alto’s WildFire in terms of malware prevention?

A

Addresses zero-day threats through dynamic and static analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Fill in the blank: Palo Alto Networks generates all native signatures _______.

A

[in-house]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does Advanced Threat Prevention utilize for blocking evasive and unknown exploits?

A

Purpose-built deep-learning and machine-learning models.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between Threat Prevention and Advanced Threat Prevention?

A

Advanced Threat Prevention includes additional features like deep-learning models.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What types of traffic does Advanced Threat Prevention protect?

A
  • Web traffic
  • Non-web traffic
  • Encrypted content
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the nature of commodity threats?

A

Less sophisticated and easier to detect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are advanced persistent threats (APTs) commonly targeting?

A
  • Intellectual property theft
  • Financial data theft
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What detection mechanisms does the Palo Alto next-generation firewall include?

A
  • Signature-based
  • Heuristics-based
  • Sandbox-based
  • Layer 7 protocol analysis-based
17
Q

What is the update frequency for protections when deployed with WildFire?

A

Every five minutes.

18
Q

What does Palo Alto Networks’ Threat Prevention prevent?

A
  • Vulnerability exploits
  • Malware
  • Botnets
19
Q

True or False: Palo Alto’s Threat Prevention can integrate with third-party solutions.

20
Q

How does Palo Alto’s IPS signature differ from legacy security devices?

A

It covers vulnerabilities per profile rather than relying solely on ports.

21
Q

What type of forensics does Palo Alto’s Threat Prevention provide?

A

Actionable, correlated forensics.