Study. uk . com
  1. Home
  2. All questions
  3. Question 268

CISSP study material · question 268 of 500

A compliance requirement demands that outbound web activity be attributed to named users and logged per user. Which firewall capability does NIST SP 800-41 say is needed?

  1. Fragment reassembly, since user identity appears only in reassembled payloads.
  2. Stateful inspection, since state tables record the initiating user.
  3. Network address translation, since translation entries map users to addresses.
  4. Application layer awareness, since a firewall handling only lower layers cannot identify individual users.
Show the answer

Answer: D. Application layer awareness, since a firewall handling only lower layers cannot identify individual users.

A firewall that only handles lower layers cannot usually identify specific users, whereas one with application layer capabilities can enforce user authentication and log events to specific users.

Source: NIST SP 800-41 Rev. 1 (NIST) — SP 800-41 Rev. 1 > 2. Overview of Firewall Technologies

Challenge yourself on this topic → Study as cards