CompTIA Tech+ (FC0-U71)SecurityHard

A company is concerned about employees installing unauthorized software or accessing malicious websites. They want to implement a solution that can inspect encrypted network traffic to identify and block such activities. Which security technology is designed to perform this function?

  1. ASecurity Information and Event Management (SIEM)
  2. BData Loss Prevention (DLP)
  3. CIntrusion Detection System (IDS)
  4. DNext-Generation Firewall (NGFW)
Show answer & explanation

Correct answer: D. Next-Generation Firewall (NGFW)

A Next-Generation Firewall (NGFW) combines traditional firewall features with advanced capabilities like deep packet inspection (DPI), intrusion prevention, and application awareness. This allows it to inspect encrypted traffic (after decryption) and block unauthorized applications or access to malicious websites.

Why the other options are wrong

  • A. A SIEM is a centralized logging and analysis system, not a traffic inspection and blocking solution.
  • B. DLP focuses on preventing sensitive data from leaving the network, not primarily blocking malicious sites or unauthorized software installations.
  • C. An IDS detects malicious activity but typically doesn't block traffic or inspect encrypted content at this level.

Next-Generation Firewall (NGFW)

A deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and advanced threat intelligence.

  • Combines traditional firewall with advanced features.
  • Performs deep packet inspection (DPI).
  • Can inspect and control application-layer traffic, including encrypted traffic (with SSL decryption).

Memory trick: NGFW: Next-Gen is for Nasty stuff in encrypted traffic.

More Security questions