Chapter 10. Implementing Network
Security Appliances
This restricts web use to only authorized sites. Examples schools restricting access to
only sites that are. Edu or to not allow sites that have adult-level content or restriction of
workplace to only allowing sites that are for work purposes. - answer Content Filter
This works on a store-and-forward model and deconstructs each packet, performs
analysis, then rebuilds the packet and forwards it on. A part of this process is removing
suspicious content in the process of rebuilding the packet. - answer Proxy Server
A system admin configures this by specifying a group of rules that define the type of
data packet, and the appropriate action to take when the packet matches the rule. -
answer Packet Filtering Firewalls
Analyze the following scenarios and determine which best simulates a content filter in
action. (Select all that apply.)
A.) A system has broken down a packet containing malicious content, and erases the
suspicious content, before rebuilding the packet.
B.) A high school student is using the school library to do research for an assignment
and cannot access certain websites due to the subject matter.
C.) A system administrator builds a set of rules based on information found in the
source IP address to allow access to an intranet.
D.) A system administrator blocks access to social media sites after the CEO complains
that work performance has decreased due to excessive social media usage at work -
answerB and D
Compare and analyze the types of firewalls available to differentiate between them.
A.) Packet filtering firewalls operate at layer 5 of the OSI model, while circuit-level
stateful inspection firewalls operate at layer 3.
B.) An appliance firewall is also known as a stateful multilayer inspection or a deep
packet inspection. An application aware firewall is a stand-alone hardware firewall that
performs the function of a firewall only.
C.) A packet filtering firewall maintains stateful information about a connection between
two hosts and implements an appliance firewall as a software application running on a
single host.
D.) An application firewall can analyze the HTTP headers to identify code that matches
a pattern, while an appliance firewall monitors all traffic passing into and out of a
network segment. - answerD
, This can inspect the contents of packets at the application layer and can analyze the
HTTP headers. It also analyzes the HTML code present in HTTP packets, to try to
identify code that matches a pattern in its threat database. - answerApplication Firewall
This operates at level 3 of the OSI model while circuit-level stateful inspection firewalls
operate at layer 5 of the model - answerPacket Filtering Firewalls
This is also known as a stateful multilayer inspection or a deep packet inspection. -
answerApplication aware Firewall
This is a stand-alone hardware firewall that performs the function of a firewall only. -
answerAppliance Firewall
True or False: A packet filtering firewall is stateless, and an application firewall is a
software application running on a single host. - answerTrue
Compare and contrast the characteristics of the various types of firewalls and select the
correct explanation of a packet filtering firewall.
A.) An administrator configures an Access Control List (ACL) to deny access to IP
addresses with specific sources
B.) A firewall that maintains stateful information about the connection
C.) A firewall that analyzes HTTP headers and the HTML code to identify code that
matches a pattern
D.) A stand-alone firewall implemented with routed interfaces or as a virtual wire
transparent firewall - answerA
This does not maintain stateful information about the connection between two hosts.
The firewall analyzes each packet independently, with no record of previously
processed packets. - answerPacket Filtering Firewalls
How do you configures a packet filtering firewall? - answerby specifying a group of
rules, called an Access Control List (ACL). Each rule defines a specific type of data
packet and the appropriate action to take when a packet matches the rule.
This is a stand-alone hardware firewall that monitors all traffic passing into and out of a
network segment. - answerAppliance Firewall
A network administrator wants to use a proxy server to prevent external hosts from
connecting directly with application servers. Which proxy server implementation will best
fit this need?
A.) Transparent proxy server
B.) Non-transparent proxy server
C.) Caching proxy server
D.) Reverse proxy server - answerD
Security Appliances
This restricts web use to only authorized sites. Examples schools restricting access to
only sites that are. Edu or to not allow sites that have adult-level content or restriction of
workplace to only allowing sites that are for work purposes. - answer Content Filter
This works on a store-and-forward model and deconstructs each packet, performs
analysis, then rebuilds the packet and forwards it on. A part of this process is removing
suspicious content in the process of rebuilding the packet. - answer Proxy Server
A system admin configures this by specifying a group of rules that define the type of
data packet, and the appropriate action to take when the packet matches the rule. -
answer Packet Filtering Firewalls
Analyze the following scenarios and determine which best simulates a content filter in
action. (Select all that apply.)
A.) A system has broken down a packet containing malicious content, and erases the
suspicious content, before rebuilding the packet.
B.) A high school student is using the school library to do research for an assignment
and cannot access certain websites due to the subject matter.
C.) A system administrator builds a set of rules based on information found in the
source IP address to allow access to an intranet.
D.) A system administrator blocks access to social media sites after the CEO complains
that work performance has decreased due to excessive social media usage at work -
answerB and D
Compare and analyze the types of firewalls available to differentiate between them.
A.) Packet filtering firewalls operate at layer 5 of the OSI model, while circuit-level
stateful inspection firewalls operate at layer 3.
B.) An appliance firewall is also known as a stateful multilayer inspection or a deep
packet inspection. An application aware firewall is a stand-alone hardware firewall that
performs the function of a firewall only.
C.) A packet filtering firewall maintains stateful information about a connection between
two hosts and implements an appliance firewall as a software application running on a
single host.
D.) An application firewall can analyze the HTTP headers to identify code that matches
a pattern, while an appliance firewall monitors all traffic passing into and out of a
network segment. - answerD
, This can inspect the contents of packets at the application layer and can analyze the
HTTP headers. It also analyzes the HTML code present in HTTP packets, to try to
identify code that matches a pattern in its threat database. - answerApplication Firewall
This operates at level 3 of the OSI model while circuit-level stateful inspection firewalls
operate at layer 5 of the model - answerPacket Filtering Firewalls
This is also known as a stateful multilayer inspection or a deep packet inspection. -
answerApplication aware Firewall
This is a stand-alone hardware firewall that performs the function of a firewall only. -
answerAppliance Firewall
True or False: A packet filtering firewall is stateless, and an application firewall is a
software application running on a single host. - answerTrue
Compare and contrast the characteristics of the various types of firewalls and select the
correct explanation of a packet filtering firewall.
A.) An administrator configures an Access Control List (ACL) to deny access to IP
addresses with specific sources
B.) A firewall that maintains stateful information about the connection
C.) A firewall that analyzes HTTP headers and the HTML code to identify code that
matches a pattern
D.) A stand-alone firewall implemented with routed interfaces or as a virtual wire
transparent firewall - answerA
This does not maintain stateful information about the connection between two hosts.
The firewall analyzes each packet independently, with no record of previously
processed packets. - answerPacket Filtering Firewalls
How do you configures a packet filtering firewall? - answerby specifying a group of
rules, called an Access Control List (ACL). Each rule defines a specific type of data
packet and the appropriate action to take when a packet matches the rule.
This is a stand-alone hardware firewall that monitors all traffic passing into and out of a
network segment. - answerAppliance Firewall
A network administrator wants to use a proxy server to prevent external hosts from
connecting directly with application servers. Which proxy server implementation will best
fit this need?
A.) Transparent proxy server
B.) Non-transparent proxy server
C.) Caching proxy server
D.) Reverse proxy server - answerD