350-701 · Question #673
A network administrator needs a solution to match traffic and allow or deny the traffic based on the type of application, not just the source or destination address and port used. Which kind of…
The correct answer is A. nextgeneration firewall. A next-generation firewall (NGFW) is the security product designed to match and control traffic based on the specific application type, rather than just traditional source/destination addresses and ports.
Question
A network administrator needs a solution to match traffic and allow or deny the traffic based on the type of application, not just the source or destination address and port used. Which kind of security product must the network administrator implement to meet this requirement?
Options
- Anextgeneration firewall
- Bweb application firewall
- Cnext generation intrusion prevention system
- Dintrusion detection system
How the community answered
(19 responses)- A84% (16)
- B5% (1)
- D11% (2)
Why each option
A next-generation firewall (NGFW) is the security product designed to match and control traffic based on the specific application type, rather than just traditional source/destination addresses and ports.
A next-generation firewall (NGFW) combines traditional firewall capabilities with advanced features like application awareness, intrusion prevention system (IPS) functionality, and deep packet inspection. This allows it to identify and control traffic based on the application generating it, regardless of the port or protocol used, providing granular control and enhanced security.
A web application firewall (WAF) specifically protects web applications from common web-based attacks (e.g., SQL injection, XSS) but focuses on HTTP/HTTPS traffic at the application layer, not general application identification across all protocols.
A next-generation intrusion prevention system (NGIPS) is designed for threat detection and prevention based on signatures and behavioral analysis, but while it can be application-aware, it's typically a component or feature *within* an NGFW, or focused on IPS functions rather than primary traffic filtering by application type.
An intrusion detection system (IDS) primarily monitors network or system activities for malicious policies and alerts on them, but does not actively block or allow traffic based on application type in a filtering capacity.
Concept tested: Next-generation firewall capabilities (application awareness)
Source: https://www.cisco.com/c/en/us/products/security/next-generation-firewalls/what-is-a-ngfw.html
Topics
Community Discussion
No community discussion yet for this question.