QuestionQ19

Security Principles

If a firewall receives traffic that is not explicitly allowed by its security policy, what action should the firewall take?

  • A Nothing
  • B Do not log and drop the traffic.
  • C Log and drop the traffic.
  • D Log and pass the traffic.
  • E Do not log and pass the traffic.
Explanation

Traffic not matched by an explicitly permitting firewall security-policy rule is implicitly denied. Logging the denied traffic provides visibility for monitoring, troubleshooting, and auditing.

Community Discussion

No comments yet. Be the first to start the discussion!