CompTIA Security+ (SY0-701)Security OperationsMedium
A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains identified by various threat intelligence feeds. The device also needs to inspect encrypted traffic for malicious content and prevent common web application attacks like SQL injection. Which of the following enterprise security tools would be MOST suitable for this comprehensive set of requirements?
- AIntrusion Detection System (IDS)
- BStateful firewall
- CNetwork Access Control (NAC)
- DNext-Generation Firewall (NGFW)
Show answer & explanationAnswer & explanation
Correct answer: D. Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) integrates advanced features beyond traditional stateful firewalls, including deep packet inspection, intrusion prevention capabilities, application awareness, and often threat intelligence integration. This allows it to block traffic based on malicious IPs/domains, inspect encrypted traffic, and mitigate web application attacks.
Why the other options are wrong
- A. An IDS detects but does not block traffic, and typically lacks deep application-layer inspection for web attacks.
- B. A stateful firewall primarily filters traffic based on port and protocol and maintains session state, but doesn't usually integrate threat intelligence or inspect encrypted application-layer content.
- C. NAC controls endpoint access to the network but does not perform traffic inspection or block malicious IPs/domains like a firewall.
Next-Generation Firewall (NGFW)
A deep packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and threat intelligence integration.
- Combines traditional firewall with IPS/IDS.
- Performs deep packet inspection (DPI).
- Includes application awareness and threat intelligence.
Memory trick: For NEXT-LEVEL protection, you need a FIREWALL that's SMART and has a lot of GADGETS.