A network security system that protects network resources by filtering messages at the application layer is:
- A.Packet Filter Firewall
- B.Proxy Firewall
- C.Stateful inspection Firewall
- D.Next-Gen Firewall
Show answer
Correct answer: B. Proxy Firewall
Explanation
The correct answer is B, Proxy Firewall. A proxy firewall, also called an application gateway, stands between the client and the server as a stand-in for both, opens each message and filters it at the application layer, so it can read a URL, a command or an attachment before passing the request on. Because it must understand the protocol it guards, a separate proxy is written for each service, and HTTP, FTP and SMTP proxies are the common ones. Option A, the packet filter firewall, reads only the IP header and the port number at the network and transport layers and cannot see what a message contains. Option C, the stateful inspection firewall, goes a step further by tracking the state of every connection, but it still works at the transport layer. Option D, the next-generation firewall, is a product category that bundles several of these techniques rather than the classical firewall defined by application layer filtering. Exam tip: a packet filter reads headers, a proxy reads the message itself.