Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 224 discussion

Actual exam question from ISC's CISSP
Question #: 224
Topic #: 1
[All CISSP Questions]

Which of the following is the MAIN difference between a network-based firewall and a host-based firewall?

  • A. A network-based firewall is stateful, while a host-based firewall is stateless.
  • B. A network-based firewall blocks network intrusions, while a host-based firewall blocks malware.
  • C. A network-based firewall controls traffic passing through the device, while a host-based firewall controls traffic destined for the device.
  • D. A network-based firewall verifies network traffic, while a host-based firewall verifies processes and applications.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CuteRabbit168
Highly Voted 2 years, 1 month ago
Selected Answer: C
A HIDS monitors processes and applications on a host. Not host-based firewall. So, D may not be the right answer.
upvoted 6 times
...
Toyeeb
Highly Voted 2 years, 1 month ago
Selected Answer: C
an Host based firewall control traffics destined for the host.
upvoted 5 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
629f731
Most Recent 10 months, 2 weeks ago
Selected Answer: C
C. Option D provides precise details about the specific types of checks performed by each type of firewall, but does not capture the general distinction in their control areas as succinctly as option C.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
The correct answer here is C. The main difference between a network-based firewall and a host-based firewall is that a network-based firewall controls traffic passing through the device, while a host-based firewall controls traffic destined for the device
upvoted 2 times
...
homeysl
1 year, 1 month ago
Selected Answer: C
C. Control is the keyword.. I thought it was D.
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: C
According to the Official ISC2 CISSP CBK Reference (4th Edition), p.513, host-based firewall offer protection if a network-based firewall fails. Host-based firewalls are also useful for microsegmentation. The Official Study Guide (9th Edition), p. 553 does not put emphasis on processes or applications. Both books assume that host-based firewalls provide an additional layer of protection that can complement network-based firewalls and differ only when they are used - in a network or at an endpoint.
upvoted 2 times
...
Demo25
1 year, 4 months ago
Selected Answer: C
C. A network-based firewall controls traffic passing through the device, while a host-based firewall controls traffic destined for the device. Network-based firewalls are deployed in line with the traffic flow, protecting the entire network. They control traffic passing through the device, and can be used to block specific types of traffic, such as incoming or outgoing traffic from certain ports or IP addresses. Host-based firewalls are operated on single computers, via OS-run software. They control traffic destined for the device, and can be used to block specific types of traffic, such as incoming or outgoing traffic from certain applications or processes.
upvoted 3 times
...
dmo_d
1 year, 6 months ago
Selected Answer: C
Question was according to a firewall not to an EDR/EPP. So C it is.
upvoted 1 times
...
Dee83
1 year, 10 months ago
C. A network-based firewall controls traffic passing through the device, while a host-based firewall controls traffic destined for the device. A network-based firewall is typically installed on a network device such as a router or a switch, and monitors and controls incoming and outgoing network traffic based on predetermined security rules. On the other hand, a host-based firewall is installed on an individual host such as a computer or a server, and monitors and controls incoming and outgoing traffic destined for that specific host. It controls the incoming traffic to the host and outgoing traffic from the host based on predetermined security rules.
upvoted 1 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: C
I go with C.
upvoted 1 times
...
sphenixfire
1 year, 11 months ago
Selected Answer: C
For and from.. but yea, c
upvoted 2 times
...
BP_lobster
2 years ago
Selected Answer: C
Chose D but realised this is invalid - a host-based firewall still verifies network traffic destined for the device! Hence C is the only remaining valid answer.
upvoted 3 times
...
rdy4u
2 years, 1 month ago
Selected Answer: D
Network-based firewalls are deployed in line with the traffic flow, protecting the entire network. Host-based firewalls are operated on single computers, via OS-run software. https://www.skillset.com/questions/what-are-the-differences-between-network-based-firewalls-and-host-based-firewalls-select-all-that-ap
upvoted 1 times
...
[Removed]
2 years, 1 month ago
Network firewalls control ingress/egress traffic flows at the network perimeter. Host firewalls control ingress/egress flows for applications on an endpoint... The description BitDefender allocates to its Host-Based Firewall is: "Monitors connections performed by your apps and provides advanced control of network connectivity", reviewing policies for my apps, I have a typical permit/deny ACL controlling which network(s), ports/protocols and direction (traffic coming into the computer for that app, traffic leaving my endpoint for that app, or both), I have an ACL for each app installed... adobe, Firefox, CCleaner. To me, this rules out D, and narrows it down to C only.
upvoted 1 times
...
rc7
2 years, 1 month ago
Answer is C. I can see why the wording can be confusing when mentioning "destined for the device" but destined can also mean bounded.
upvoted 1 times
...
JAckThePip
2 years, 1 month ago
Answer D "Host based firewalls are on individual computers. Network firewalls are placed 'in-line' generally just before the border router. Considering defense in depth, host based firewalls and network firewalls can be used at the same time."
upvoted 3 times
...
krassko
2 years, 2 months ago
Selected Answer: D
D. "So a modern firewall needs to monitor operating system events from the start until the end of processes, loading and unloading modules, and be able to link this information to data at the moment the packet is filtered in the driver." https://www.apriorit.com/dev-blog/543-how-host-based-firewall-works
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...