Which combination of firewall and inspection technologies would provide layered, comprehensive protection for a modern enterprise running a mix of traditional data center workloads, cloud-native applications, and public-facing web applications?
Correct Answer: NGFW for perimeter and segment-level application-aware policy, distributed/host-based firewalls (potentially leveraging eBPF) for east-west and cloud-native workload protection, a WAF for public-facing web applications, and IPS for active in-line threat blocking
Explanation: NGFW at the perimeter/segments, distributed/host-based (eBPF-capable) firewalls for east-west and cloud-native protection, a WAF for public web apps, and IPS for active blocking together provide layered protection, unlike a single perimeter-only stateful firewall, a WAF as the sole control everywhere, distributed firewalls with no perimeter control, IDS substituted where active blocking is required, or disabling host-based firewalls on cloud-native workloads.
Correct Answer: NGFW for perimeter and segment-level application-aware policy, distributed/host-based firewalls (potentially leveraging eBPF) for east-west and cloud-native workload protection, a WAF for public-facing web applications, and IPS for active in-line threat blocking
Explanation: NGFW at the perimeter/segments, distributed/host-based (eBPF-capable) firewalls for east-west and cloud-native protection, a WAF for public web apps, and IPS for active blocking together provide layered protection, unlike a single perimeter-only stateful firewall, a WAF as the sole control everywhere, distributed firewalls with no perimeter control, IDS substituted where active blocking is required, or disabling host-based firewalls on cloud-native workloads.