Exam Questions and CORRECT Answers
Compartmentalization - CORRECT ANSWER - breaks up a network into different areas.
dividing a network into security zones. intranets, extranets, enclaves etc.
segmentation - CORRECT ANSWER - dividing a network for efficient management.
firewall - CORRECT ANSWER - primary mechanism to provide security separation
between two networks.
used for going between internal network and the internet
used to keep people from HR out of accounting network and vice versa for example.
types of firewalls - CORRECT ANSWER - packet filter
proxy
stateful inspection
web App Firewall - CORRECT ANSWER - special purpose typ eof firewall. controls all of
the traffic to and from that server.
What does every firewall require? - CORRECT ANSWER - you to configure rules of
some kind.
Access Control List - CORRECT ANSWER - rules that you load onto a router and apply
to an interface.
How do you know what rules you should put on the firewall? - CORRECT ANSWER -
your organization's policy tells you what rules you need.
, default deny - CORRECT ANSWER - what most firewalls on the market today are. you
put in rules to allow necessary traffic and everything else is automatically denied.
default allow - CORRECT ANSWER - everything automatically accepted.
Excessive rules - CORRECT ANSWER - rule creep- new rules are added when new
people come in. always add a comment to your firewall rules os the next person in the job will
have some idea why the rule was added.
packet filter - CORRECT ANSWER - most common on routers
load an ACL; apply to interface
when you create the rules for ACL, you can filter on information only from the OSI layers 3 and
4 headers. specifically, you can filter on the source and destination IP addresses, the source and
destination port number, and the protocol type such as TCP/UDP/ICMP etc.
two types of firewall packets - CORRECT ANSWER - TCP and UDP
Proxy firewall - CORRECT ANSWER - operate at OSI layer 7.
most important thing to note about a proxy? - CORRECT ANSWER - nothing goes
through a proxy. traffic goes to the device. traffic goes from the device. no trafficc goes through
the device.
What are the two separate connections for the internet in relation to the proxy? - CORRECT
ANSWER - one from the client to the proxy and one from the proxy to the internet server.
internet has no idea client system exists; its communication is with the proxy/