- Home
- All questions
- Question 260
CISSP study material · question 260 of 500
An architect argues that a stateless filter is adequate because it will catch spoofed packets and abusive header options. Which two limitations does NIST SP 800-41 identify? Choose two.
Show the answer
Answer: A. Stateless filters generally cannot detect that network layer addressing has been spoofed.
C. Stateless filters cannot recognise standards-permitted options used maliciously, such as IP source routing.
Packet filters are vulnerable to attacks exploiting the protocol stack: many cannot detect spoofed or altered addressing information, or options permitted by standards but generally used maliciously.
Source: NIST SP 800-41 Rev. 1 (NIST) — SP 800-41 Rev. 1 > 2.1.1 Packet Filtering