Test your Firewall knowledge with a free interactive quiz — 28 questions with answers and explanations. No signup needed to play.
Question 1/12Score 0
What does "TLS inspection" (decrypt-inspect-re-encrypt) on an NGFW allow the firewall to do that it otherwise could not?
In this round
What does "TLS inspection" (decrypt-inspect-re-encrypt) on an NGFW allow the firewall to do that it otherwise could not?
A security review finds that a company's production database security group has a wide-open ingress rule allowing 0.0.0.0/0 on the database port. What is the most appropriate fix?
A DMZ (demilitarized zone) in network architecture is best described as:
Why might a team explicitly use a NACL to deny traffic from a known-malicious IP range, in addition to relying on security groups?
What distinguishes a stateful firewall from a stateless one?
What specifically does a Web Application Firewall (WAF) protect against that a general network firewall typically does not?
Why is logging denied and allowed traffic (flow logs, firewall logs) considered a critical part of firewall operations, not an optional extra?
What is a practical downside of stateful firewalls compared to stateless ones?
A team relies entirely on their firewall to secure a web application and skips input validation, reasoning that "the firewall blocks bad traffic." Why is this reasoning flawed?
In a three-tier segmented architecture (load balancer, app, database), which of these rule configurations best reflects the principle of least privilege at the network layer?
What is the primary function of a firewall?
What risk do temporary "allow my IP for debugging" firewall rules create if they are not cleaned up after use?