Sophos Engineer ET80 – Sophos Firewall Overview Exam
Questions With 100% Verified Correct Answers |2026 Updated
Guaranteed Pass.
What is Application control? - Answer -This is a service used to reduce the attack surface by
restricting what applications are allowed
What is Synchronized App control? - Answer -Sophos Firewall sees app traffic that does not
match a signature, but Sophos Endpoint shares the app name, path and category to the Sophos
firewall for classification, so the firewall can categorise and control traffic
What happens in the Exploitation Phase of the Attack Kill Chain? - Answer -The use of a
vulnerability to execute code on the victims machine
What types of attacks are used to exploit Web Servers? - Answer -XSS, SQL Injection, Protocol
Violations and Cross Site Scripting
How does Sophos Web Server Protection work? - Answer -It use pre-configured templates to
protect Web Servers. It works as a reverse proxy in the DMZ for inbound traffic. It uses a Web
Application firewall to filter traffic, sign cookies and scan for malware. It can also authenticate
users before they access the web server
What is an IPS? - Answer -Intrusion Prevention System
1
Page
1|Page
, What does an IPS do? - Answer -Monitor network for malicious activity and takes action to block
intrusions
What happens in the Command and Control Phase of the Attack Kill Chain? - Answer -The
installed malware makes a connection to a remote command and control centre for remote
manipulation of the Infected machine
What does Advanced Threat Protection do? - Answer -It monitors all outgoing traffic and
detects and blocks malicious outgoing traffic. This stops infected machines from contacting
command and control centres. If this happens, and alert is recorded within the Control Centre
of Sophos Firewall containing additional information to allow an Admin to clear the device up
while the Firewall isolates the device to stop further infections across the network
What does ATP stand for? - Answer -Advanced Threat Protection
What happens in the Behaviour phase of the Attack Kill Chain? - Answer -Depending on the
malware installed, the behaviour of the infected machine will vary but can include encrypting
files for Ransom, or Spyware that steals and downloads information such as passwords or
payment information
How does Sophos Automatic Device Isolation work? - Answer -Server Protection and Intercept X
are used to assign each device a health status. If a device is compromised, the device can be
automatically isolated from other areas of the network via the firewall and communicating with
other devices. This limits infection of other devices on the network
2
Page
2|Page
Questions With 100% Verified Correct Answers |2026 Updated
Guaranteed Pass.
What is Application control? - Answer -This is a service used to reduce the attack surface by
restricting what applications are allowed
What is Synchronized App control? - Answer -Sophos Firewall sees app traffic that does not
match a signature, but Sophos Endpoint shares the app name, path and category to the Sophos
firewall for classification, so the firewall can categorise and control traffic
What happens in the Exploitation Phase of the Attack Kill Chain? - Answer -The use of a
vulnerability to execute code on the victims machine
What types of attacks are used to exploit Web Servers? - Answer -XSS, SQL Injection, Protocol
Violations and Cross Site Scripting
How does Sophos Web Server Protection work? - Answer -It use pre-configured templates to
protect Web Servers. It works as a reverse proxy in the DMZ for inbound traffic. It uses a Web
Application firewall to filter traffic, sign cookies and scan for malware. It can also authenticate
users before they access the web server
What is an IPS? - Answer -Intrusion Prevention System
1
Page
1|Page
, What does an IPS do? - Answer -Monitor network for malicious activity and takes action to block
intrusions
What happens in the Command and Control Phase of the Attack Kill Chain? - Answer -The
installed malware makes a connection to a remote command and control centre for remote
manipulation of the Infected machine
What does Advanced Threat Protection do? - Answer -It monitors all outgoing traffic and
detects and blocks malicious outgoing traffic. This stops infected machines from contacting
command and control centres. If this happens, and alert is recorded within the Control Centre
of Sophos Firewall containing additional information to allow an Admin to clear the device up
while the Firewall isolates the device to stop further infections across the network
What does ATP stand for? - Answer -Advanced Threat Protection
What happens in the Behaviour phase of the Attack Kill Chain? - Answer -Depending on the
malware installed, the behaviour of the infected machine will vary but can include encrypting
files for Ransom, or Spyware that steals and downloads information such as passwords or
payment information
How does Sophos Automatic Device Isolation work? - Answer -Server Protection and Intercept X
are used to assign each device a health status. If a device is compromised, the device can be
automatically isolated from other areas of the network via the firewall and communicating with
other devices. This limits infection of other devices on the network
2
Page
2|Page