ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 198 - SY0-701 discussion

Report
Export

The CIRT is reviewing an incident that involved a human resources recruiter exfiltration sensitive company data. The CIRT found that the recruiter was able to use HTTP over port 53 to upload documents to a web server. Which of the following security infrastructure devices could have identified and blocked this activity?

A.
WAF utilizing SSL decryption
Answers
A.
WAF utilizing SSL decryption
B.
NGFW utilizing application inspection
Answers
B.
NGFW utilizing application inspection
C.
UTM utilizing a threat feed
Answers
C.
UTM utilizing a threat feed
D.
SD-WAN utilizing IPSec
Answers
D.
SD-WAN utilizing IPSec
Suggested answer: B

Explanation:

An NGFW (Next-Generation Firewall) utilizing application inspection could have identified and blocked the unusual use of HTTP over port 53. Application inspection allows NGFWs to analyze traffic at the application layer, identifying and blocking suspicious or non-standard protocol usage, such as HTTP traffic on DNS port 53.

NGFW utilizing application inspection: Inspects traffic at the application layer and can block non-standard protocol usage, such as HTTP over port 53.

WAF utilizing SSL decryption: Focuses on protecting web applications and decrypting SSL traffic but may not detect the use of HTTP over port 53.

UTM utilizing a threat feed: Provides comprehensive security but may not focus specifically on application layer inspection.

SD-WAN utilizing IPSec: Enhances secure WAN connections but is not primarily designed to inspect and block specific application traffic.

asked 02/10/2024
Deepak PSK
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first