A firewall can obscure hosts and complicate enumeration during testing. Which statement best reflects this?

Prepare for the eLearnSecurity Junior Penetration Tester exam with our comprehensive quiz platform. Improve your skills with multiple-choice questions, detailed explanations, and exam tips. Get exam ready with ease!

Multiple Choice

A firewall can obscure hosts and complicate enumeration during testing. Which statement best reflects this?

Explanation:
Firewalls regulate traffic between networks by applying rules that permit or deny packets. This control can mask internal hosts from view and make enumeration and port discovery more difficult during testing. When a probe hits a network behind a firewall, many hosts may not respond, responses can be delayed or appear as filtered, and only traffic that matches permitted rules gets through, complicating the tester’s mapping of the network. This behavior—controlling traffic between networks and obscuring hosts to hinder enumeration and port discovery—best describes the firewall’s effect in a test environment. Other options don’t fit because encryption by default isn’t a firewall function (that’s encryption handled by TLS/VPNs), automatic patching isn’t performed by a firewall (patch management handles that), and providing open wireless access isn’t a firewall capability (that would be an access point or wireless controller).

Firewalls regulate traffic between networks by applying rules that permit or deny packets. This control can mask internal hosts from view and make enumeration and port discovery more difficult during testing. When a probe hits a network behind a firewall, many hosts may not respond, responses can be delayed or appear as filtered, and only traffic that matches permitted rules gets through, complicating the tester’s mapping of the network. This behavior—controlling traffic between networks and obscuring hosts to hinder enumeration and port discovery—best describes the firewall’s effect in a test environment.

Other options don’t fit because encryption by default isn’t a firewall function (that’s encryption handled by TLS/VPNs), automatic patching isn’t performed by a firewall (patch management handles that), and providing open wireless access isn’t a firewall capability (that would be an access point or wireless controller).

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy