ENGINEER V21.0 CORE STUDY GUIDE &
MASTER QUESTION BANK FULLY
GRADED A+ BUNDLE
This premium, verified study bank delivers the
ultimate preparation resource for the Sophos
Firewall v21.0 Engineer Exam (ET80). Every
multiple-choice question features highlighted correct
answers and comprehensive, deep-dive technical
rationales tailored to ensure a perfect passing score.
Module 1: Sophos Firewall Architecture &
Basics (Questions 1-10)
Q1. What is the default IP address used to
access the Sophos Firewall web administrator
console out of the box?
A) 192.168.1.1
B) 172.16.16.16
C) 10.0.1.1
D) 192.168.16.16
Correct Answer: B) 172.16.16.16
Rationale: Out of the box, Sophos Firewall
assigns 172.16.16.16 to Port A (LAN interface) by
default for initial setup configuration.
,Q2. Which default port is appended to the IP
address to access the Sophos Firewall Web UI
admin console via HTTPS?
A) 8443
B) 443
C) 4444
D) 8080
Correct Answer: C) 4444
Rationale: Sophos Firewall uses port 4444 for
secure HTTPS web administrator console
access.
Q3. What is the fundamental security paradigm
behind Sophos Zero Trust Network Access
(ZTNA)?
A) Trust but verify everything on the network
B) Never trust, verify everything explicitly
C) Trust all internal network segments automatically
D) Perimeter-only defense verification
Correct Answer: B) Never trust, verify everything
explicitly
Rationale: The core pillar of Zero Trust
architecture dictates that no user or device is
trusted by default, whether inside or outside the
perimeter.
,Q4. In the Attack Kill Chain, which phase
immediately follows Weaponization?
A) Exploitation
B) Delivery
C) Installation
D) Actions on Objectives
Correct Answer: B) Delivery
Rationale: The exact progression is
Reconnaissance -> Weaponization -> Delivery ->
Exploitation -> Installation -> Command &
Control -> Actions on Objectives.
Q5. What mechanism does Sophos Lateral
Protection use to prevent malware from
spreading inside a network?
A) Broad network isolation via perimeter routers
B) Isolating compromised endpoints directly at the
local segment level using Synchronized Security
C) Blocking all inbound WAN ports across the entire
region
D) Automatically restarting the central switch
Correct Answer: B) Isolating compromised endpoints
directly at the local segment level using
Synchronized Security
Rationale: Lateral Protection uses Security
Heartbeat to tell healthy endpoints to refuse
, internal traffic from a compromised peer,
effectively micro-segmenting the threat.
Q6. Where in the Sophos Firewall Web UI do you
navigate to verify your subscriptions and
hardware serial registration?
A) System Services > Features
B) Administration > Licensing
C) Backup & Firmware > Licensing
D) Profiles > Licenses
Correct Answer: B) Administration > Licensing
Rationale: Licensing evaluation, active
subscriptions, and synchronized registration
statuses are entirely managed under
Administration > Licensing.
Q7. What is the primary purpose of the Secure
Storage Master Key (SSMK) in Sophos Firewall
v21.0?
A) It decrypts the admin password during daily
console logins
B) It encrypts sensitive data stored within backups,
such as passwords and private keys
C) It serves as a secondary authentication factor for
administrative SSH sessions
D) It unlocks the firmware downgrade capability
Correct Answer: B) It encrypts sensitive data stored