Ch 2 Flashcards

(19 cards)

1
Q

What is a firewall?

A

A firewall is a network security device that monitors incoming and outgoing network traffic and permits or blocks data packets based on a set of security rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the major types of firewalls?

A

The major types of firewalls include:
- Packet Filter
- Application Gateway
- Circuit Level Gateway
- Stateful Packet Inspection
- And More..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Packet Filter?

A

The most basic type of firewall, also known as a ‘Screening’ firewall, operates on the transport and network layer of TCP/IP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does a Packet Filter examine?

A

A Packet Filter examines a packet’s:
1. Source address
2. Destination address
3. Source port
4. Destination port
5. Protocol type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the disadvantages of a Packet Filter?

A

Disadvantages include:
- Does not compare packets
- No authentication
- Susceptible to SYN and Ping flood attacks
- Does not track packets
- Does not look at the packet data, just the header
- Not necessarily the most secure firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an Application Gateway?

A

Also known as Application proxy or application-level proxy, it operates on the Application layer and examines the connection between the client and the server applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the disadvantages of an Application Gateway?

A

Disadvantages include:
- Requires more system resources
- Susceptible to flooding attacks (SYN, Ping)
- Time taken to authenticate user
- Once connection is made, packets are not checked.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Circuit Level Gateway?

A

Circuit-level gateways monitor TCP handshakes and other network protocol session initiation messages across the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the advantages of Circuit Level Gateways?

A

Advantages include:
- More secure than application gateways
- External systems do not see internal systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Stateful Packet Inspection?

A

Stateful Packet Inspection monitors the state of active connections and uses this information to determine which network packets to allow through the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the characteristics of Stateful Packet Inspection?

A

Characteristics include:
- Tracks sessions of network connections
- Aware of context of packets
- Recognizes whether source IP is within the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are Hybrid Firewalls?

A

Hybrid Firewalls take multiple approaches to their firewall implementations, such as using SPI and circuit level gateways together.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a Network Host-Based Firewall?

A

A firewall installed on each individual server that controls incoming and outgoing network traffic, running on top of the operating system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a Dual-Homed Host?

A

A networked device built with two network interface cards (NICs), expanded version of the Network host firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a Router-Based Firewall?

A

Usually the first line of defense, it uses simple packet filtering and can be preconfigured by the vendor for specific user needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Screened Host?

A

A combination of firewalls using a bastion host and screening router, similar in concept to the dual-homed host.

17
Q

What is the purpose of using a Proxy Server?

A

A Proxy Server prevents the outside world from gathering information about your internal network and provides valuable log information.

18
Q

What is Network Address Translation (NAT)?

A

NAT translates internal IP addresses to public addresses and can explicitly map ports to internal addresses for web servers.

19
Q

What are the critical components of network security solutions?

A

Firewalls and proxy servers are critical for network security solutions, with various solutions available that range in price and features.