CNIT 455 Exam I
T/F A Packet Filter is hardware that limits connectivity - Answer-F (Software)
Packet filters block _______ and ______ traffic - Answer-ingress, egress
Packet filters use ____ based filtering - Answer-rule
Packet filter rules are combined into ________ - Answer-rulesets
T/F A good practice with packet filters is to allow what you want then deny all else. - Answer-T
A firewall always includes a ______ ______ - Answer-packet filter
T/F All packet filters are firewalls - Answer-F (Firewalls contain packet filters, not vice versa)
T/F Windows firewall, iptables, and pfsense are examples of software "firewalls" - Answer-T
T/F Packet filters are often used as a replacement in the IP stack on modern implementations. - Answer-
F (uncommon)
T/F Packet filters are often implemented as a specialized network device. - Answer-T
,One should always use __ rather than ___ when configuring a packet filter, as the latter is far easier to
spoof. - Answer-IP, DNS
When filtering by IP, one should control access based on the ______/__________ IP address. - Answer-
source/destination
T/F Packet filters are vulnerable to IP address spoofing via ARP. - Answer-T
LSRR stands for - Answer-Loose Source Record Routing
T/F LSRR tells packets specific routes to gain access to otherwise unreachable networks. - Answer-T
T/F LSRR prevents machines from spoofing addresses. - Answer-F (Enables spoofing, as net traffic can
still find the machine)
T/F You should always enable LSRR on border routers and firewalls - Answer-F (DISABLE IT)
UDP and TCP communication is based on numbered _____ - Answer-ports
T/F UDP and TCP source and destination ports are standardized. - Answer-F (only destination)
UDP and TCP ______ ports are chosen randomly, from port ____ and above - Answer-source, 1024
The two types of port filtering are ______ and ________ - Answer-Static, dynamic
, Static port filtering involves only allowing traffic based on ____ number or IP/____ number combination
- Answer-port
In static port filtering, each packet is checked _____________ - Answer-independently
Dynamic port filtering is also known as ________ ______ __________ - Answer-stateful packet
inspection
Dynamic port filtering checks the _______ of the packet as well as ______ and ___________ addresses -
Answer-context, source, destination
T/F Destination Static Port Filtering involves examining and filtering based on source port number -
Answer-F (destination you dip)
The major limitation of Destination Static Port Filtering is that it only works if a server responds to
incoming messages on the _________ ____ - Answer-receiving port
In source static port forwarding, source ports are typically randomly chosen from numbers above ____ -
Answer-1023
In source static port forwarding, after a server sends a message using a random port > 1023, the return
traffic will be _______ by the firewall. - Answer-blocked
To work around the blocking caused by SSPF, you must ______ incoming traffic for ports > 1023 -
Answer-allow
T/F Allowing traffic for SSPF is a massive security problem. - Answer-T
T/F A Packet Filter is hardware that limits connectivity - Answer-F (Software)
Packet filters block _______ and ______ traffic - Answer-ingress, egress
Packet filters use ____ based filtering - Answer-rule
Packet filter rules are combined into ________ - Answer-rulesets
T/F A good practice with packet filters is to allow what you want then deny all else. - Answer-T
A firewall always includes a ______ ______ - Answer-packet filter
T/F All packet filters are firewalls - Answer-F (Firewalls contain packet filters, not vice versa)
T/F Windows firewall, iptables, and pfsense are examples of software "firewalls" - Answer-T
T/F Packet filters are often used as a replacement in the IP stack on modern implementations. - Answer-
F (uncommon)
T/F Packet filters are often implemented as a specialized network device. - Answer-T
,One should always use __ rather than ___ when configuring a packet filter, as the latter is far easier to
spoof. - Answer-IP, DNS
When filtering by IP, one should control access based on the ______/__________ IP address. - Answer-
source/destination
T/F Packet filters are vulnerable to IP address spoofing via ARP. - Answer-T
LSRR stands for - Answer-Loose Source Record Routing
T/F LSRR tells packets specific routes to gain access to otherwise unreachable networks. - Answer-T
T/F LSRR prevents machines from spoofing addresses. - Answer-F (Enables spoofing, as net traffic can
still find the machine)
T/F You should always enable LSRR on border routers and firewalls - Answer-F (DISABLE IT)
UDP and TCP communication is based on numbered _____ - Answer-ports
T/F UDP and TCP source and destination ports are standardized. - Answer-F (only destination)
UDP and TCP ______ ports are chosen randomly, from port ____ and above - Answer-source, 1024
The two types of port filtering are ______ and ________ - Answer-Static, dynamic
, Static port filtering involves only allowing traffic based on ____ number or IP/____ number combination
- Answer-port
In static port filtering, each packet is checked _____________ - Answer-independently
Dynamic port filtering is also known as ________ ______ __________ - Answer-stateful packet
inspection
Dynamic port filtering checks the _______ of the packet as well as ______ and ___________ addresses -
Answer-context, source, destination
T/F Destination Static Port Filtering involves examining and filtering based on source port number -
Answer-F (destination you dip)
The major limitation of Destination Static Port Filtering is that it only works if a server responds to
incoming messages on the _________ ____ - Answer-receiving port
In source static port forwarding, source ports are typically randomly chosen from numbers above ____ -
Answer-1023
In source static port forwarding, after a server sends a message using a random port > 1023, the return
traffic will be _______ by the firewall. - Answer-blocked
To work around the blocking caused by SSPF, you must ______ incoming traffic for ports > 1023 -
Answer-allow
T/F Allowing traffic for SSPF is a massive security problem. - Answer-T