QuestionQ198

Information Security Program

Which of the following is the BEST way to determine whether a firewall is configured to provide comprehensive perimeter defense?

  • A A port scan of the firewall from an internal source
  • B A simulated denial of service (DoS) attack against the firewall
  • C A validation of the current firewall rule set
  • D A ping test from an external source
Explanation

Validating the active firewall rule set verifies whether traffic controls comprehensively enforce the intended perimeter security policy, including allowed services, sources, destinations, and deny rules.

Community Discussion

No comments yet. Be the first to start the discussion!