Question

Difficulty: MediumNetwork Components Roles and Functions

An organization is deploying a dedicated network segment for industrial control systems. The network team needs to enforce deep packet inspection, application-level policy enforcement, and threat prevention between this industrial segment and the corporate intranet. Which network component is best suited to perform these specific security functions at the boundary?

  1. Next-Generation Firewall (NGFW)Answer
  2. B
    Standard Layer 2 Switch
  3. C
    Type 1 Bare-Metal Hypervisor
  4. D
    LLDP-enabled Layer 2 Discovery Agent

Answer

Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) integrates traditional stateful firewall capabilities with Layer 7 application inspection, intrusion prevention systems (IPS), and threat protection, making it the appropriate choice to protect boundaries between different functional network zones.

Step-by-Step Solution

1
Analyze the operational requirements specified in the scenario
The requirement identifies deep packet inspection, application-level security enforcement, and threat mitigation between two network zones.
Security functions above Layer 3 require specialized appliances capable of inspecting traffic payloads beyond basic header routing.
2
Evaluate the capabilities of network components at boundary points
Next-Generation Firewalls combine stateful inspection with advanced services like application control and intrusion prevention.
Deploying an NGFW at the network boundary ensures policy control and threat protection for incoming and outgoing segment traffic.

Key Concept

Network Security Appliance Roles (NGFW vs. L2 Devices & Hypervisors)
Rate this question