Lecture 3 pt. 2 Flashcards

1
Q

The NGFW is ______ based

A

Routing based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The NGFWs security policy is either based on _-_____ or ____ __________:

A

Based on 6-tuple or user generated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The NGFWs decision making process includes ________ ____s or ______s

A

security zones or levels

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The NGFW works on levels

A

2-4 and 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is the NGFW stateful or stateless?

A

Stateful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Fortinet, Palo Alto Checkpoint are examples of

A

NGFWs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Cisco Firepower, Juniper FW/ AWS Security Groups ?

A

NGFWs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Recite how User-ID and App-ID features are a cornerstone in NGFWs (3 parts)

A
  1. User-ID and App-ID is used in conjunction with a network segmented into zones
  2. Access privileges are tied to users and groups, rather than specific devices in a zone
  3. This ensures users have the appropriate access/privileges regardless of where they access the network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does network segmentation affect the attack surface?

A

it decreases the size of the attack surface by preventing lateral movement between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name this: a group of one or more physical/virtual firewall interfaces and the network
segments connected to those interfaces.

A

Security zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

You should always create a separate security zone to isolate/protect an area when there is a division in(3):

A
  1. Functionality
  2. App use
  3. Access privileges
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Network segmentation is the logical grouping of network assets/resources to implement 3 things:

A

Services
Authentication Requirements
Security Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In ________ segmentation the topology is fixed in the architecture, _______ segmentation is more flexible as it requires no wiring

A

physical; logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the emerging practice for access control, threat detection, and mitigation?

A

Use a single consolidated policy for all 3 and apply it across the entire network

rather than having separate systems handling each function in different

How well did you know this?
1
Not at all
2
3
4
5
Perfectly