Firewalls & ACLs
You will learn how stateful firewalls track connections, how ACLs are evaluated top-down with an implicit deny, and how zone-based policies are structured in iptables/nftables and vendor firewalls. Interviewers probe this first because misordered rules and stateless-vs-stateful confusion are classic real-world failure modes.
on this pageshowhide
explore
- The Filter's Inputs8 questions
- The Price of Remembering4 questions
- Port Numbers as Claims4 questions
- Choosing the Chokepoint12 questions
- Perimeter, Host or Hypervisor4 questions
- The Unfiltered Direction4 questions
- The Outward-Facing Tier4 questions
- The Ageing Rulebase12 questions
- Rules Nobody Dares Delete4 questions
- The Temporary Permit4 questions
- Order as a Weakness4 questions
questions
page 2 of 2A plant manager refuses to sign any firewall rule deletion. How do you still retire reach an intruder could inherit?
basics
~20 sChange what the plant manager is being asked to approve: reversible disables at a time he chooses, owners claiming the rules they need, narrowing where deletion is refused, and the residual exposure escalated to whoever owns both risks.
Finance wants the firewall SKU with half the session capacity. How do you defend the larger one?
basics
~10 sTranslate the number into a business failure. The ceiling counts concurrent flows, the population claiming them is unbounded, and at the ceiling the box refuses new connections while existing ones look perfectly healthy.
showing 31–32 of 32