WAF Flashcards

1
Q

Firewalls in general

What happens in a layer 4 firewall?

A

Every request and response is distinct, only cares about IP addresses and ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Firewalls in general

What happens in a layer 5 firewall?

A

Requests and responses are combined by keeping session information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Firewalls in general

Why is a layer 5 firewall better than 3 or 4?

A

More contextual security, less admin overhead

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Firewalls in general

What happens in a layer 7 firewall?

A

Requests and responses are combined by keeping session information, understands HTTP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Firewalls in general

What can only a layer 7 firewall guard against?

important

A

Protocol-specific attacks, like XSS maybe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Firewalls in general

Do layer 7 firewalls break SSL?

A

Yes. Firewall is the SSL term, device can deep-inspect HTTP protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Firewalls in general

What 4 things can a layer 7 firewall do with content it sees?

important

A

Inspect it (logging), block it (reject request), replace it (redact on way out), tag it (spam)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Firewalls in general

What other layer 7 protocol can firewalls understand other than HTTP?

A

SMTP (intelligent email handling)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly