Study. uk . com
  1. Home
  2. All questions
  3. Question 270

CISSP study material · question 270 of 500

A diagram labels a firewall's outside interface unprotected and its inside interface protected. Why does NIST SP 800-41 describe this labelling as often inappropriate?

  1. Interfaces cannot be labelled until the ruleset is written.
  2. The outside interface is protected by the upstream provider's filtering.
  3. Policy works in both directions - for instance preventing executable code from leaving the perimeter.
  4. Both interfaces are inside the trust boundary once translation is enabled.
Show the answer

Answer: C. Policy works in both directions - for instance preventing executable code from leaving the perimeter.

SP 800-41 says calling something protected or unprotected is often inappropriate because a firewall's policies can work in both directions, such as stopping executable code being sent outward.

Source: NIST SP 800-41 Rev. 1 (NIST) — SP 800-41 Rev. 1 > 2.1 Firewall Technologies

Challenge yourself on this topic → Study as cards