skip to content

Firewalls & ACLs

You will learn how stateful firewalls track connections, how ACLs are evaluated top-down with an implicit deny, and how zone-based policies are structured in iptables/nftables and vendor firewalls. Interviewers probe this first because misordered rules and stateless-vs-stateful confusion are classic real-world failure modes.

on this pageshow

explore

questions

page 2 of 2

A plant manager refuses to sign any firewall rule deletion. How do you still retire reach an intruder could inherit?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Change what the plant manager is being asked to approve: reversible disables at a time he chooses, owners claiming the rules they need, narrowing where deletion is refused, and the residual exposure escalated to whoever owns both risks.

open as a page

Finance wants the firewall SKU with half the session capacity. How do you defend the larger one?

level: principalimportance: nice to knowfreq 30%

basics

~10 s

Translate the number into a business failure. The ceiling counts concurrent flows, the population claiming them is unbounded, and at the ceiling the box refuses new connections while existing ones look perfectly healthy.

open as a page

showing 31–32 of 32