700-270 · Question #17
Which three features are considered next-generation firewall capabilities? (Choose three)
The correct answer is B. application visibility and control C. NAT E. VPN. There is an issue with the provided answer key that I should flag before explaining: B, C, E is not correct for this question. NAT (C) and VPN (E) are traditional firewall capabilities, not next-generation differentiators. The correct answer should be A, B, D. --- Why A, B, and D
Question
Which three features are considered next-generation firewall capabilities? (Choose three)
Options
- Aexternal intelligence to enhance controls
- Bapplication visibility and control
- CNAT
- Didentity-based controls
- EVPN
- FRFC-based inspection
How the community answered
(19 responses)- A5% (1)
- B95% (18)
Explanation
There is an issue with the provided answer key that I should flag before explaining: B, C, E is not correct for this question. NAT (C) and VPN (E) are traditional firewall capabilities, not next-generation differentiators. The correct answer should be A, B, D.
Why A, B, and D are the correct NGFW features:
Next-generation firewalls go beyond port/protocol inspection by adding application visibility and control (B) - identifying apps regardless of port or protocol - identity-based controls (D) - enforcing policies by user or group rather than just IP address - and external intelligence (A) - consuming threat intel feeds to dynamically update security decisions.
Why the distractors are wrong:
- C (NAT) and E (VPN) are features of traditional firewalls and UTM devices; NGFWs may include them, but they don't define the "next-generation" distinction.
- F (RFC-based inspection) is the opposite of what NGFWs do - traditional firewalls rely on RFC-defined port/protocol rules, while NGFWs use deep packet inspection to see what the traffic actually is.
Memory tip: Think of NGFW as adding three "who/what/why" layers on top of a traditional firewall - what app (application control), who's using it (identity), and what's known about threats externally (intelligence). NAT and VPN are plumbing, not intelligence.
If this question came from a specific study guide or practice test, I'd recommend verifying it against official vendor documentation (Cisco, Palo Alto, etc.) - the answer key appears to contain an error.
Topics
Community Discussion
No community discussion yet for this question.