Systems Security Certified Practitioner – SSCP – Question0933

Which type of firewall can be used to track connectionless protocols such as UDP and RPC?

A.
Stateful inspection firewalls
B. Packet filtering firewalls
C. Application level firewalls
D. Circuit level firewalls

Correct Answer: A

Explanation:

Packets in a stateful inspection firewall are queued and then analyzed at all OSI layers, providing a more complete inspection of the data. By examining the state and context of the incoming data packets, it helps to track the protocols that are considered “connectionless”, such as UDP-based applications and Remote Procedure Calls (RPC). Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 91).