Lecture 10 Pt. 4 Flashcards
What does NGFW stand for?
Next Generation Firewall
NGFW provides advanced security features beyond traditional firewalls.
What is the primary purpose of Threat Prevention in NGFW?
To challenge today’s threat landscape using a multi-layered defense approach.
Name two vendors that offer NGFW solutions.
- Palo Alto
- Checkpoint
What integrated service does Palo Alto’s NGFW provide?
Integrated threat prevention services.
What key feature does Palo Alto’s WildFire provide?
Cloud-based malware analysis.
True or False: Palo Alto’s threat prevention relies solely on predefined ports.
False
What technology does Palo Alto use to identify and add context to all traffic?
- User-ID
- App-ID
What type of attacks does Palo Alto Networks Advanced Threat Prevention aim to stop?
Zero-day attacks.
What is the function of Palo Alto’s WildFire in terms of malware prevention?
Addresses zero-day threats through dynamic and static analysis.
Fill in the blank: Palo Alto Networks generates all native signatures _______.
[in-house]
What does Advanced Threat Prevention utilize for blocking evasive and unknown exploits?
Purpose-built deep-learning and machine-learning models.
What is the difference between Threat Prevention and Advanced Threat Prevention?
Advanced Threat Prevention includes additional features like deep-learning models.
What types of traffic does Advanced Threat Prevention protect?
- Web traffic
- Non-web traffic
- Encrypted content
What is the nature of commodity threats?
Less sophisticated and easier to detect.
What are advanced persistent threats (APTs) commonly targeting?
- Intellectual property theft
- Financial data theft
What detection mechanisms does the Palo Alto next-generation firewall include?
- Signature-based
- Heuristics-based
- Sandbox-based
- Layer 7 protocol analysis-based
What is the update frequency for protections when deployed with WildFire?
Every five minutes.
What does Palo Alto Networks’ Threat Prevention prevent?
- Vulnerability exploits
- Malware
- Botnets
True or False: Palo Alto’s Threat Prevention can integrate with third-party solutions.
True
How does Palo Alto’s IPS signature differ from legacy security devices?
It covers vulnerabilities per profile rather than relying solely on ports.
What type of forensics does Palo Alto’s Threat Prevention provide?
Actionable, correlated forensics.