nerdexam
Cisco

700-270 · Question #17

Which three features are considered next-generation firewall capabilities? (Choose three)

The correct answer is B. application visibility and control C. NAT E. VPN. There is an issue with the provided answer key that I should flag before explaining: B, C, E is not correct for this question. NAT (C) and VPN (E) are traditional firewall capabilities, not next-generation differentiators. The correct answer should be A, B, D. --- Why A, B, and D

Understanding Next-Generation Firewall Technology and Concepts

Question

Which three features are considered next-generation firewall capabilities? (Choose three)

Options

  • Aexternal intelligence to enhance controls
  • Bapplication visibility and control
  • CNAT
  • Didentity-based controls
  • EVPN
  • FRFC-based inspection

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    95% (18)

Explanation

There is an issue with the provided answer key that I should flag before explaining: B, C, E is not correct for this question. NAT (C) and VPN (E) are traditional firewall capabilities, not next-generation differentiators. The correct answer should be A, B, D.


Why A, B, and D are the correct NGFW features:

Next-generation firewalls go beyond port/protocol inspection by adding application visibility and control (B) - identifying apps regardless of port or protocol - identity-based controls (D) - enforcing policies by user or group rather than just IP address - and external intelligence (A) - consuming threat intel feeds to dynamically update security decisions.

Why the distractors are wrong:

  • C (NAT) and E (VPN) are features of traditional firewalls and UTM devices; NGFWs may include them, but they don't define the "next-generation" distinction.
  • F (RFC-based inspection) is the opposite of what NGFWs do - traditional firewalls rely on RFC-defined port/protocol rules, while NGFWs use deep packet inspection to see what the traffic actually is.

Memory tip: Think of NGFW as adding three "who/what/why" layers on top of a traditional firewall - what app (application control), who's using it (identity), and what's known about threats externally (intelligence). NAT and VPN are plumbing, not intelligence.

If this question came from a specific study guide or practice test, I'd recommend verifying it against official vendor documentation (Cisco, Palo Alto, etc.) - the answer key appears to contain an error.

Topics

#NGFW Capabilities#Application Visibility and Control#Firewall Features#Network Security

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice