Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard
A security analyst is investigating a sophisticated attack where an attacker managed to bypass perimeter defenses and establish a persistent foothold within the internal network. The attacker is using command-and-control (C2) communication disguised as normal HTTP traffic over port 80. Which advanced network security technology is specifically designed to detect and block such evasive, internal threats by analyzing traffic behavior and protocol anomalies?
- AAccess Control List (ACL)
- BStateful Packet Inspection (SPI)
- CTraditional Firewall
- DNext-Generation Firewall (NGFW)
Show answer & explanationAnswer & explanation
Correct answer: D. Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) goes beyond traditional port and protocol inspection. It incorporates Deep Packet Inspection (DPI), intrusion prevention systems (IPS), and application awareness to identify and block evasive threats like C2 traffic disguised as legitimate protocols, even on standard ports like 80.
Why the other options are wrong
- A. ACLs filter traffic based on IP addresses and ports, similar to traditional firewalls, and are insufficient for this threat.
- B. SPI tracks connection states but doesn't analyze application layer content to detect disguised C2 traffic.
- C. Traditional firewalls primarily inspect ports and IP addresses, which would not detect C2 over port 80.
Next-Generation Firewall (NGFW)
A deep-packet inspection firewall that moves beyond port/protocol inspection and includes additional capabilities like application awareness, integrated intrusion prevention, and threat intelligence.
- Performs deep packet inspection (DPI).
- Understands application context, not just ports.
- Integrates IPS and threat intelligence.
- Effective against sophisticated, evasive threats like C2.
Memory trick: NGFW: The smart firewall that knows what apps are really doing.