CISA FINAL EXAM 2026 QUESTIONS AND ANSWERS
GRADED A+
✔✔An application gateway - ✔✔is essentially another sort of proxy server. The internal
client first establishes a connection with the application gateway. The application
gateway determines if the connection should be allowed or not and then establishes a
connection with the destination computer. All communications go through two
connections- client to application gateway and application gateway to destination. The
application gateway monitors all traffic against its rules before deciding whether or not
to forward it. As with the other proxy server types, the application gateway is the only
address seen by the outside world so the internal network is protected.
✔✔ADV of Application Gateway - ✔✔• An application-level gateway is the best way to
protect against hacking because it can define with detail rules that describe the type of
user or connection that is or is not permitted. It analyzes in detail each package, not
only in layers one through four of the OSI model but also layers five through seven,
which means that it reviews the commands of each higher level protocol (HTTP, FTP,
SNMP, etc.)
• It hides the design of the internal network
• It can be used to implement strong authentication.
✔✔DISADV of Application Gateway - ✔✔• It reduces network performance.
• It must be tailored to specific applications.
✔✔For a remote access server - ✔✔there is a device (server) that asks for a username
and password before entering the network. This is good when accessing private
networks, but it can be mapped or scanned from the Internet creating security exposure.
✔✔A proxy server - ✔✔is generally put in place to boost performance of the network,
but can act as a sort of firewall as well. Proxy servers also hide your internal addresses
as well so that all communications appear to originate from the proxy server itself. A
proxy server will cache pages that have been requested. If User A goes to Yahoo.com
the proxy server actually sends the request to Yahoo.com and retrieves the web page. If
User B then connects to Yahoo.com the proxy server just sends the information it
already retrieved for User A so it is returned much faster than having to get it from
Yahoo.com again. You can configure a proxy server to block access to certain web sites
and filter certain port traffic to protect your internal network.
✔✔Proxy servers - ✔✔can provide protection based on the IP address and ports.
However, an individual is needed who really knows how to do this, and applications can
use different ports for the different sections of the program.
✔✔Port scanning - ✔✔works when there is a very specific task to complete, but not
when trying to control what comes from the Internet (or when all the ports available
need to be controlled). For example, the port for Ping (echo request) could be blocked
, and the IP addresses would be available for the application and browsing, but would not
respond to Ping.
✔✔Firewall Architectures - ✔✔
✔✔Screening router - ✔✔is the most basic type of firewall architecture deployed. An
external router is placed between the untrusted networks and a security policy is
implemented using ACLs. Very weak security with little protection (but better than
nothing).
✔✔A dual homed gateway (or bastion host) - ✔✔is a system with two network
interfaces that sits between an untrusted and trusted network. A bastion host is typically
a hardened system with robust security measures. The dual homed gateway functions
as a proxy server for the trusted network and may be configured to require user
authentication. It masks the network structure, but may cause slower network
performance than the screening router alone.
✔✔A screened host gateway/firewall - ✔✔is a bastion host and an external screening
router. The bastion host is the only host accessible from the untrusted network
(providing web services, ftp, etc.). This approach implements basic network layer
security (packet filtering) and application server security (proxy services).
✔✔A dual-homed firewall system - ✔✔is a more restrictive form of a screened-host
firewall system, configuring one interface for information servers and another for private
network host computers.
✔✔A screened-subnet firewall - ✔✔also used as a demilitarized zone (DMZ), utilizes
two packet filtering routers and a bastion host. This provides the most secure firewall
system, since it supports both network- and application-level security while defining a
separate DMZ network. Publicly available services are placed on bastion hosts in the
DMZ. Disadvantages include high cost, maintenance and troubleshooting.
✔✔Advanced Encryption Standard (AES) - ✔✔a public algorithm (block cipher... not
stream) that supports keys from 128 to 256 bits in size, not only provides good security,
but provides speed and versatility across a variety of computer platforms. AES runs
securely and efficiently on large computers, desktop computers and even small devices
such as smart cards. AES is a symmetric (or private) key cipher.
✔✔Data Encryption Standard (DES) - ✔✔is not considered a strong cryptographic
solution since its entire key space can be brute forced by large computer systems within
a relatively short period of time. DES is a symmetric (or private) key cipher consisting of
an algorithm and a key (block cipher... not stream).
✔✔Triple DES - ✔✔can take up to three times longer than DES to perform encryption
and decryption. Unacceptably slow and wont work well with applications requiring fast
GRADED A+
✔✔An application gateway - ✔✔is essentially another sort of proxy server. The internal
client first establishes a connection with the application gateway. The application
gateway determines if the connection should be allowed or not and then establishes a
connection with the destination computer. All communications go through two
connections- client to application gateway and application gateway to destination. The
application gateway monitors all traffic against its rules before deciding whether or not
to forward it. As with the other proxy server types, the application gateway is the only
address seen by the outside world so the internal network is protected.
✔✔ADV of Application Gateway - ✔✔• An application-level gateway is the best way to
protect against hacking because it can define with detail rules that describe the type of
user or connection that is or is not permitted. It analyzes in detail each package, not
only in layers one through four of the OSI model but also layers five through seven,
which means that it reviews the commands of each higher level protocol (HTTP, FTP,
SNMP, etc.)
• It hides the design of the internal network
• It can be used to implement strong authentication.
✔✔DISADV of Application Gateway - ✔✔• It reduces network performance.
• It must be tailored to specific applications.
✔✔For a remote access server - ✔✔there is a device (server) that asks for a username
and password before entering the network. This is good when accessing private
networks, but it can be mapped or scanned from the Internet creating security exposure.
✔✔A proxy server - ✔✔is generally put in place to boost performance of the network,
but can act as a sort of firewall as well. Proxy servers also hide your internal addresses
as well so that all communications appear to originate from the proxy server itself. A
proxy server will cache pages that have been requested. If User A goes to Yahoo.com
the proxy server actually sends the request to Yahoo.com and retrieves the web page. If
User B then connects to Yahoo.com the proxy server just sends the information it
already retrieved for User A so it is returned much faster than having to get it from
Yahoo.com again. You can configure a proxy server to block access to certain web sites
and filter certain port traffic to protect your internal network.
✔✔Proxy servers - ✔✔can provide protection based on the IP address and ports.
However, an individual is needed who really knows how to do this, and applications can
use different ports for the different sections of the program.
✔✔Port scanning - ✔✔works when there is a very specific task to complete, but not
when trying to control what comes from the Internet (or when all the ports available
need to be controlled). For example, the port for Ping (echo request) could be blocked
, and the IP addresses would be available for the application and browsing, but would not
respond to Ping.
✔✔Firewall Architectures - ✔✔
✔✔Screening router - ✔✔is the most basic type of firewall architecture deployed. An
external router is placed between the untrusted networks and a security policy is
implemented using ACLs. Very weak security with little protection (but better than
nothing).
✔✔A dual homed gateway (or bastion host) - ✔✔is a system with two network
interfaces that sits between an untrusted and trusted network. A bastion host is typically
a hardened system with robust security measures. The dual homed gateway functions
as a proxy server for the trusted network and may be configured to require user
authentication. It masks the network structure, but may cause slower network
performance than the screening router alone.
✔✔A screened host gateway/firewall - ✔✔is a bastion host and an external screening
router. The bastion host is the only host accessible from the untrusted network
(providing web services, ftp, etc.). This approach implements basic network layer
security (packet filtering) and application server security (proxy services).
✔✔A dual-homed firewall system - ✔✔is a more restrictive form of a screened-host
firewall system, configuring one interface for information servers and another for private
network host computers.
✔✔A screened-subnet firewall - ✔✔also used as a demilitarized zone (DMZ), utilizes
two packet filtering routers and a bastion host. This provides the most secure firewall
system, since it supports both network- and application-level security while defining a
separate DMZ network. Publicly available services are placed on bastion hosts in the
DMZ. Disadvantages include high cost, maintenance and troubleshooting.
✔✔Advanced Encryption Standard (AES) - ✔✔a public algorithm (block cipher... not
stream) that supports keys from 128 to 256 bits in size, not only provides good security,
but provides speed and versatility across a variety of computer platforms. AES runs
securely and efficiently on large computers, desktop computers and even small devices
such as smart cards. AES is a symmetric (or private) key cipher.
✔✔Data Encryption Standard (DES) - ✔✔is not considered a strong cryptographic
solution since its entire key space can be brute forced by large computer systems within
a relatively short period of time. DES is a symmetric (or private) key cipher consisting of
an algorithm and a key (block cipher... not stream).
✔✔Triple DES - ✔✔can take up to three times longer than DES to perform encryption
and decryption. Unacceptably slow and wont work well with applications requiring fast