NGFW & WAF
You will learn what makes a firewall 'next-generation' — application and user awareness, deep packet inspection, TLS interception — and how WAFs like ModSecurity with the OWASP Core Rule Set defend HTTP traffic. Interviewers use it to test whether you understand layer-7 defense and the trade-offs of breaking TLS to inspect it.
on this pageshowhide
explore
- Depth of Inspection16 questions
- Application, Not Port4 questions
- Your Own Issuing Authority4 questions
- The Shrinking Readable Share4 questions
- Users Behind Addresses4 questions
- Controlling the Exits12 questions
- Converging on Default Deny4 questions
- The Unproxyable Estate4 questions
- Resolving Where You Watch4 questions
- Judging a Request11 questions
- Paranoia and Its Price4 questions
- Retiring a Stopgap Rule4 questions
- Inline, Beside or Ahead3 questions
questions
page 2 of 2Your inspection root can mint any name: what custody evidence shows a customer's auditor that no insider mints one silently, and what does it cost?
basics
~20 sControls whose failure a party outside your team would notice: a non-exportable hardware key, a witnessed generation ceremony, an issuance log held append-only by another owner, and name constraints the auditor can read for themselves. They buy detectability, not impossibility.
A transparent inline WAF sits in your virtual network's path; a routing change stops sending traffic through it — how do you find out?
basics
~20 sNot from an outage — traffic keeps flowing and the application keeps working, so a transparent device leaves the path silently. You find out only from positive evidence that judgment is still happening, per path: a marker the origin can check, judged-request counts compared with served-request counts, and a probe that must be blocked.
Forcing egress through the proxy on a 24/6 line gives you one window - how do you sequence it, and what justifies refusing a 03:00 revert that hands an implant the direct path out again?
basics
~20 sDo not spend the window discovering what breaks. Run the policy in log-only mode first, build the destination inventory from records the gateway already produces, enforce in rings, and agree revert criteria in writing beforehand.
How do you prove what share of your endpoints still resolve through the sanctioned filtering resolver?
basics
~20 sNot from resolver logs alone — they cannot show a host that asked somebody else. Join the querying sources to the asset inventory, add egress records for other resolver destinations, and make the endpoint prove the path.
Raising the Core Rule Set to paranoia level 3 across a shared ingress tier needs replicas finance will not fund - what do you propose?
basics
~20 sStop selling a fleet-wide level. Measure both prices per route, the CPU per request and the legitimate requests refused, then buy paranoia level 3 only where warranted and hand finance priced options with the refusal count attached.
A WAF rule is the only thing between attackers and an unconfirmed bug in a partner's code, with no owner or expiry — how do you resolve that?
basics
~20 sTreat it as an ownership and contract problem, not a rule problem. Name an internal owner with a dated review, get a testable build and a reproducible test written into the supplier agreement, and put the residual risk in front of whoever owns the partner relationship to accept in writing with an expiry.
One inspection stack serves ten tenants: what does your unclassified-traffic rule say, who signs for it, and what hides behind an allow?
basics
~20 sThe default is a risk acceptance, not a technical preference, and a provider cannot accept risk for a customer. Aim at per-tenant defaults: deny for new tenants from onboarding, a dated migration with a log-only phase for the rest, and a named tenant signature on every allow.
showing 31–39 of 39