CompTIA Security+ (SY0-701)Security OperationsHard

A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains, as identified by various threat intelligence feeds. This device also needs to inspect HTTP/HTTPS traffic for web application attacks like SQL injection and cross-site scripting. Which type of security control BEST combines these functionalities?

  1. AWeb Application Firewall (WAF)
  2. BNext-Generation Firewall (NGFW)
  3. CStateful Firewall
  4. DIntrusion Prevention System (IPS)
Show answer & explanation

Correct answer: B. Next-Generation Firewall (NGFW)

A Next-Generation Firewall (NGFW) integrates traditional firewall capabilities with advanced features like deep packet inspection, application awareness, intrusion prevention (IPS), and often, built-in threat intelligence feeds to block known malicious sources and inspect application-layer attacks.

Why the other options are wrong

  • A. A WAF specifically protects web applications from attacks like SQL injection and XSS by inspecting HTTP/HTTPS traffic, but it doesn't typically incorporate broad threat intelligence feeds for blocking malicious IPs/domains at the network level.
  • C. A stateful firewall primarily focuses on filtering traffic based on port/protocol and connection state, lacking advanced threat intelligence integration and application-layer inspection for web attacks.
  • D. An IPS detects and prevents intrusions based on signatures and anomalies, but typically operates at lower layers and doesn't inherently integrate threat intelligence feeds or specifically target web application attacks as a WAF would.

Next-Generation Firewall (NGFW)

A deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and intelligence from outside the firewall.

  • Combines traditional firewall with IPS and application awareness.
  • Often integrates threat intelligence feeds.
  • Provides deeper inspection for web attacks and malware.

Memory trick: For 'Next-Gen' threats, you need a 'Next-Gen' firewall that does it 'All'.

More Security Operations questions