SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security architect is designing a secure network for a new cloud-based application. The architect wants to ensure that all traffic entering and leaving the application's subnet is inspected and filtered based on a set of predefined security rules. Which security control would best fulfill this requirement?

  1. ANetwork Access Control (NAC)
  2. BWeb Application Firewall (WAF)
  3. CHost-based Intrusion Detection System (HIDS)
  4. DNetwork-based Firewall
Show answer & explanation

Correct answer: D. Network-based Firewall

A network-based firewall is designed to inspect and filter network traffic between different network segments (like subnets) based on predefined rules, such as IP addresses, ports, and protocols. This capability directly addresses the requirement to inspect and filter all traffic entering and leaving the application's subnet.

Why the other options are wrong

  • A. NAC controls which devices can connect to the network, not primarily traffic flow between subnets.
  • B. WAF protects web applications from specific web-based attacks, not general network traffic filtering between subnets.
  • C. HIDS monitors a single host for suspicious activity, not traffic between network segments.

Network-based Firewall

A security device or software that monitors and controls incoming and outgoing network traffic based on predetermined security rules, typically operating at the network perimeter or between network segments (subnets).

  • Filters traffic based on IP, port, protocol.
  • Operates at network layer (mostly).
  • Protects network segments.
  • Can be stateful or stateless.

Memory trick: Firewall guards the gate, WAF the web, NAC the entry.

More Security Operations and Administration questions