nerdexam
CompTIA

SY0-301 · Question #860

A network device that protects an enterprise based only on source and destination addresses is BEST described as:

The correct answer is D. Simple packet filtering. Simple (or stateless) packet filtering examines each packet in isolation based solely on header information such as source IP address, destination IP address, and port numbers - without maintaining any state about connections. It does not inspect packet content or track…

Security architecture

Question

A network device that protects an enterprise based only on source and destination addresses is BEST described as:

Options

  • AIDS.
  • BACL.
  • CStateful packet filtering.
  • DSimple packet filtering.

How the community answered

(17 responses)
  • B
    6% (1)
  • C
    6% (1)
  • D
    88% (15)

Explanation

Simple (or stateless) packet filtering examines each packet in isolation based solely on header information such as source IP address, destination IP address, and port numbers - without maintaining any state about connections. It does not inspect packet content or track connection state. An IDS (Intrusion Detection System) inspects traffic for attack signatures. An ACL (Access Control List) is a configuration mechanism, not a device type. Stateful packet filtering tracks the state of active connections, allowing it to make smarter decisions. Only simple packet filtering fits the description of acting purely on source and destination addresses.

Topics

#packet filtering#firewall types#stateless filtering#network access control

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice