An organization is deploying a dedicated network segment for industrial control systems. The network team needs to enforce deep packet inspection, application-level policy enforcement, and threat prevention between this industrial segment and the corporate intranet. Which network component is best suited to perform these specific security functions at the boundary?
- Next-Generation Firewall (NGFW)Answer
- BStandard Layer 2 Switch
- CType 1 Bare-Metal Hypervisor
- DLLDP-enabled Layer 2 Discovery Agent
Answer
Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) integrates traditional stateful firewall capabilities with Layer 7 application inspection, intrusion prevention systems (IPS), and threat protection, making it the appropriate choice to protect boundaries between different functional network zones.
Step-by-Step Solution
Key Concept
Network Security Appliance Roles (NGFW vs. L2 Devices & Hypervisors)