350-401 Question 296
Select 3An enterprise network administrator is configuring a next-generation firewall (NGFW) to secure the network against evolving threats. They need to allow internet access to users while also ensuring application-level visibility, intrusion prevention, and blocking of malicious URLs. Which key features should the administrator enable or configure on the NGFW to achieve these requirements?
- A
Application awareness and control
- B
Intrusion Prevention System (IPS)
- C
Static packet filtering
- D
URL filtering
- E
Virtual Private Network (VPN) support
Show answer and explanation
Correct answers: A, B, D
Explanation
To secure a network against evolving threats, an NGFW must leverage advanced features such as application awareness and control, intrusion prevention systems, and URL filtering. These capabilities provide granular visibility into application traffic, detect and block malicious activities, and restrict access to harmful websites. Legacy capabilities like static packet filtering or unrelated features like VPN support do not meet the requirements outlined in the scenario.
- A. Correct.
Application awareness and control is a key feature of next-generation firewalls, allowing them to identify and control applications based on their signatures or behaviors. This is critical for achieving application-level visibility and control.
- B. Correct.
Intrusion Prevention System (IPS) is a core function of NGFWs, enabling them to detect and prevent malicious attacks at the network and application layers.
- C. Incorrect.
Static packet filtering is a legacy firewall capability and does not provide application-level visibility or advanced threat protection. It only examines packet headers, which is insufficient for next-generation requirements.
- D. Correct.
URL filtering is an essential feature of NGFWs that blocks access to malicious or unauthorized websites, ensuring secure and controlled internet usage.
- E. Incorrect.
Virtual Private Network (VPN) support allows secure remote access but is unrelated to application-level visibility, intrusion prevention, or URL filtering. It does not directly address the stated requirements.