Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard
A small business is setting up its first network and is concerned about protecting against common network attacks. They want to implement a solution that can inspect network traffic at the application layer, enforce security policies based on application type, and provide stateful inspection capabilities. Which network security technology would best meet these requirements?
- AStateful Firewall
- BNext-Generation Firewall (NGFW)
- CNetwork Address Translation (NAT)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: B. Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) combines traditional stateful inspection with deeper application-layer inspection (Layer 7), intrusion prevention, and advanced threat intelligence, directly addressing the need for application-based security policies and stateful inspection.
Why the other options are wrong
- A. A stateful firewall performs stateful inspection but generally lacks the application-layer awareness required to enforce policies based on application type.
- C. NAT translates IP addresses and ports to conserve public IP addresses and provide a layer of obscurity, but it is not a security technology for inspecting traffic or enforcing policies.
- D. An IDS detects malicious activity but does not actively block traffic or enforce application-based security policies.
Next-Generation Firewall (NGFW)
An NGFW is a deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and intelligence from outside the firewall.
- Combines traditional firewall features with advanced capabilities.
- Performs deep packet inspection at the application layer (Layer 7).
- Integrates intrusion prevention (IPS) and advanced threat intelligence.
Memory trick: NGFW: The 'Smart Wall' that sees inside apps.