skip to content

NGFW & WAF

You will learn what makes a firewall 'next-generation' — application and user awareness, deep packet inspection, TLS interception — and how WAFs like ModSecurity with the OWASP Core Rule Set defend HTTP traffic. Interviewers use it to test whether you understand layer-7 defense and the trade-offs of breaking TLS to inspect it.

on this pageshow

explore

questions

page 2 of 2

Your inspection root can mint any name: what custody evidence shows a customer's auditor that no insider mints one silently, and what does it cost?

level: principalimportance: should knowfreq 30%

basics

~20 s

Controls whose failure a party outside your team would notice: a non-exportable hardware key, a witnessed generation ceremony, an issuance log held append-only by another owner, and name constraints the auditor can read for themselves. They buy detectability, not impossibility.

open as a page

A transparent inline WAF sits in your virtual network's path; a routing change stops sending traffic through it — how do you find out?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

Not from an outage — traffic keeps flowing and the application keeps working, so a transparent device leaves the path silently. You find out only from positive evidence that judgment is still happening, per path: a marker the origin can check, judged-request counts compared with served-request counts, and a probe that must be blocked.

open as a page

Forcing egress through the proxy on a 24/6 line gives you one window - how do you sequence it, and what justifies refusing a 03:00 revert that hands an implant the direct path out again?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Do not spend the window discovering what breaks. Run the policy in log-only mode first, build the destination inventory from records the gateway already produces, enforce in rings, and agree revert criteria in writing beforehand.

open as a page

How do you prove what share of your endpoints still resolve through the sanctioned filtering resolver?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Not from resolver logs alone — they cannot show a host that asked somebody else. Join the querying sources to the asset inventory, add egress records for other resolver destinations, and make the endpoint prove the path.

open as a page

You report that eighty-five percent of egress is inspected — what denominator makes that honest, and what can an adversary keep out of it?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

The denominator must cover every egress path and come from a source independent of the inspection device, or you divide what the device saw by what the device saw. Paths crossing no control are uncounted, not unread.

open as a page

On a shared terminal-server address, how do you attribute one flow to one user?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

An agent on the host gives each session its own source-port range and reports which range belongs to which user. The firewall attributes a flow by source port, not address; anything outside a range maps to nobody.

open as a page

Raising the Core Rule Set to paranoia level 3 across a shared ingress tier needs replicas finance will not fund - what do you propose?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Stop selling a fleet-wide level. Measure both prices per route, the CPU per request and the legitimate requests refused, then buy paranoia level 3 only where warranted and hand finance priced options with the refusal count attached.

open as a page

A WAF rule is the only thing between attackers and an unconfirmed bug in a partner's code, with no owner or expiry — how do you resolve that?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Treat it as an ownership and contract problem, not a rule problem. Name an internal owner with a dated review, get a testable build and a reproducible test written into the supplier agreement, and put the residual risk in front of whoever owns the partner relationship to accept in writing with an expiry.

open as a page

One inspection stack serves ten tenants: what does your unclassified-traffic rule say, who signs for it, and what hides behind an allow?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

The default is a risk acceptance, not a technical preference, and a provider cannot accept risk for a customer. Aim at per-tenant defaults: deny for new tenants from onboarding, a dated migration with a log-only phase for the rest, and a named tenant signature on every allow.

open as a page

showing 31–39 of 39