ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 207 - SY0-701 discussion

Report
Export

A security engineer needs to configure an NGFW to minimize the impact of the increasing number of various traffic types during attacks. Which of the following types of rules is the engineer the most likely to configure?

A.
Signature-based
Answers
A.
Signature-based
B.
Behavioral-based
Answers
B.
Behavioral-based
C.
URL-based
Answers
C.
URL-based
D.
Agent-based
Answers
D.
Agent-based
Suggested answer: B

Explanation:

To minimize the impact of the increasing number of various traffic types during attacks, a security engineer is most likely to configure behavioral-based rules on a Next-Generation Firewall (NGFW). Behavioral-based rules analyze the behavior of traffic patterns and can detect and block unusual or malicious activity that deviates from normal behavior.

Behavioral-based: Detects anomalies by comparing current traffic behavior to known good behavior, making it effective against various traffic types during attacks.

Signature-based: Relies on known patterns of known threats, which might not be as effective against new or varied attack types.

URL-based: Controls access to websites based on URL categories but is not specifically aimed at handling diverse traffic types during attacks.

Agent-based: Typically involves software agents on endpoints to monitor and enforce policies, not directly related to NGFW rules.

asked 02/10/2024
henk Bouman
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first