200-201 Question 102
Select 4A cybersecurity analyst is configuring a Next-Generation Firewall (NGFW) in an enterprise environment. One of the primary goals is to prevent and detect advanced threats while ensuring granular control over applications and users. Which features of the NGFW should the analyst enable to achieve this objective?
- A
Application visibility and control
- B
Intrusion prevention system (IPS)
- C
URL filtering
- D
Packet filtering based on source and destination IP addresses only
- E
User identity-based access control
Show answer and explanation
Correct answers: A, B, C, E
Explanation
Next-Generation Firewalls (NGFWs) combine advanced features such as application visibility and control, IPS, URL filtering, and user identity-based access control to provide comprehensive protection against modern threats. Unlike traditional firewalls that rely on basic packet filtering, NGFWs are designed to detect and mitigate advanced attacks while ensuring granular management of applications and users.
- A. Correct.
Application visibility and control is a key feature of NGFWs that allows granular control over specific applications, ensuring security and performance.
- B. Correct.
NGFWs often include an Intrusion Prevention System (IPS) to detect and block advanced threats in real-time.
- C. Correct.
URL filtering helps block access to malicious or non-compliant websites, which is an important security feature of NGFWs.
- D. Incorrect.
Packet filtering based solely on source and destination IP addresses is a feature of traditional firewalls, not NGFWs, and lacks advanced threat detection capabilities.
- E. Correct.
User identity-based access control enables the NGFW to enforce policies based on user roles, providing enhanced security and compliance.