ANSWERS RATED A+
✔✔What is the purpose of a security policy?
-To authenticate the process by which users and devices are identified and granted
access to the network
-To monitor the network security and make sure the firewall is configured properly to
prevent inappropriate usage
-To make it more difficult for hackers to locate a security hole in a network's gateway
-To describe how a company wants to approach security, including rules of conduct and
the determination of acceptable risk - ✔✔-To describe how a company wants to
approach security, including rules of conduct and the determination of acceptable risk
✔✔What question would you ask to get specific information on user restrictions?
-What kinds of network traffic will you allow?
-Will the computers be locked away from the public, or will they have access to the
hardware?
-Will users be allowed to login at any time, from any location, to any machine?
-Who should be allowed to access your services? - ✔✔-Will users be allowed to login at
any time, from any location, to any machine?
✔✔Content Filtering Services applies to which of the following traffic protocols? (Select
all that apply.)
-HTTPS
-FTP
-HTTP
-Email attachments - ✔✔-HTTP
-HTTPS
✔✔If the appliance loses connection to the SonicWALL site rating library: (Select all that
apply.)
-CFS blocks all web traffic (based on configuration)
-CFS continues to operate using the last ratings seen
-CFS allows all web traffic (based on configuration)
,-CFS must use its internal logic to identify which traffic to block - ✔✔-CFS blocks all
web traffic (based on configuration)
-CFS allows all web traffic (based on configuration)
✔✔With SonicWALL CFS, network administrators have a flexible tool to provide
comprehensive filtering based on which of the following? (Select all that apply.)
-Allowed domain designations
-Time of day
-SMTP
-Keywords
-LDAP Groups
-Forbidden domain designations
-FTP - ✔✔-Allowed domain designations
-Time of day
-Keywords
-Forbidden domain designations
✔✔The default CFS policy when assigned "Via Users and Zones Screens" should be
the most restrictive.
-True
-False - ✔✔True
✔✔The SonicWALL Log can be exported in the following formats:
(Choose all that apply)
-Log View
-Comma-separated value (CSV)
-Tab Delimited
-Plain text - ✔✔-Comma-separated value (CSV)
-Plain text
✔✔Which SonicWALL security services use the Deep Packet Inspection engine?
(Select all that apply)
-IPS
-Anti-Spyware
-GVC
-GAV
-CFS - ✔✔-IPS
-Anti-Spyware
-GAV
-CFS
, ✔✔A SonicWALL security appliance configured with Gateway Anti-Virus verifies and
enforces the Desktop Anti-Virus client to the downstream workstation.
-True
-False - ✔✔-False
✔✔The SonicWALL GAV engine can perform base64 decoding without ever
reassembling the entire base64 encoded email stream.
-True
-False - ✔✔-True
✔✔When you select "Prevent All" in the IPS Global Settings of the SonicWALL security
appliance for High Priority Attacks, this allows all blocked attacks to be entered into the
Log file of the security appliance.
-True
-False - ✔✔-False
✔✔SonicWALL GAV includes advanced decompression technology that can
automatically decompress and scan files on a per packet basis to search for viruses and
malware.
-True
-False - ✔✔-True
✔✔The SonicWALL security appliance maintains an Event log for tracking potential
security threats.
-True
-False - ✔✔-True
✔✔Which Security Services of the SonicWALL security appliance use the SonicWALL
Deep Packet Inspection engine?
-IPS, GAV, Anti-Spyware, and Viewpoint
-IPS, Anti-Spyware, Content Filtering
-IPS, GAV, and Anti-Spyware
-Global VPN Client - ✔✔-IPS, GAV, and Anti-Spyware
✔✔In order for SonicWALL's Deep Packet Inspection engine to provide protection,
where must GAV, IPS, and/or Gateway Anti-Spyware be configured?
-Firewall rules