Exam 9: Firewalls and Intrusion Prevention Systems

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A prime disadvantage of an application-level gateway is the additional processing overhead on each connection.

Free
(True/False)
4.8/5
(33)
Correct Answer:
Verified

True

An intruder transmitting packets from the outside with a source IP address field containing an address of an internal host is known as IP address _________.

Free
(Short Answer)
4.7/5
(43)
Correct Answer:
Verified

spoofing

________ control controls access to a service according to which user is attempting to access it.

Free
(Multiple Choice)
4.8/5
(35)
Correct Answer:
Verified

A

_________ control determines the direction in which particular service requests may be initiated and allowed to flow through the firewall.

(Multiple Choice)
4.9/5
(35)

A _________ configuration involves stand-alone firewall devices plus host-based firewalls working together under a central administrative control.

(Multiple Choice)
4.8/5
(34)

A __________ gateway sets up two TCP connections,one between itself and a TCP user on an inner host and one between itself and a TCP user on an outside host.

(Multiple Choice)
4.7/5
(39)

The __________ protocol is an example of a circuit-level gateway implementation that is conceptually a "shim-layer" between the application layer and the transport layer and does not provide network-layer gateway services.

(Short Answer)
4.8/5
(29)

A __________ firewall controls the traffic between a personal computer or workstation on one side and the Internet or enterprise network on the other side.

(Short Answer)
4.9/5
(44)

__________ looks for deviation from standards set forth in RFCs.

(Multiple Choice)
4.9/5
(27)

A _________ consists of a set of computers that interconnect by means of a relatively unsecure network and makes use of encryption and special protocols to provide security.

(Multiple Choice)
4.8/5
(39)

A ________ uses encryption and authentication in the lower protocol layers to provide a secure connection through an otherwise insecure network,typically the Internet.

(Short Answer)
4.9/5
(31)

The countermeasure to tiny fragment attacks is to discard packets with an inside source address if the packet arrives on an external interface.

(True/False)
4.8/5
(37)

The firewall can protect against attacks that bypass the firewall.

(True/False)
4.9/5
(32)

Snort Inline adds three new rule types: drop,reject,and _________.

(Short Answer)
4.9/5
(27)

Typical for SOHO applications,a __________ is a single router between internal and external networks with stateless or full packet filtering.

(Multiple Choice)
4.8/5
(33)

__________ protocols operate in networking devices,such as a router or firewall,and will encrypt and compress all traffic going into the WAN and decrypt and uncompress traffic coming from the WAN.

(Short Answer)
4.8/5
(31)

__________ scans for attack signatures in the context of a traffic stream rather than individual packets.

(Multiple Choice)
4.9/5
(42)

The firewall may be a single computer system or a set of two or more systems that cooperate to perform the firewall function.

(True/False)
4.8/5
(37)

An example of a circuit-level gateway implementation is the __________ package.

(Multiple Choice)
4.8/5
(35)

An important aspect of a distributed firewall configuration is security monitoring.

(True/False)
4.8/5
(30)
Showing 1 - 20 of 45
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)