HomeSG Firewall Fundamental Exam Ver.1 Certification ExamSG Firewall Fundamental Exam Ver.1Full nameEmail addressGenderSelectMaleFemaleOtherPrefer not to sayCurrent statusSelectSchool studentCollege studentWorking professionalJob seekerTeacher/TrainerOther I agree that my details and score may be stored for quiz administration.Start QuizQuestion 1 of 50Trap QuestionsHard4 mark(s)1. A firewall shows repeated denied TCP SYN packets but no completed handshakes. What does this alone prove?Select one answer.That data was stolenThat the destination service is vulnerableThat the source is definitely compromisedOnly that connection attempts were observed and deniedNATHard4 mark(s)2. An administrator changes only the destination NAT rule for a published server. External clients still fail because the security policy references the wrong destination object for that platform's processing order. What concept caused the failure?Select one answer.Wi-Fi roamingNTP driftMAC agingPre-NAT versus post-NAT policy matchingTroubleshootingHard4 mark(s)3. A firewall drops large packets across a VPN while small pings succeed. What is the most likely issue?Select one answer.Duplicate DNS MX recordMissing VLAN nameIncorrect username onlyPath MTU or fragmentation problemFirewall TypesEasy1 mark(s)4. What does a stateful firewall track?Select one answer.Active connection stateScreen resolutionOnly usernamesOnly cable lengthFirewall ArchitectureEasy2 mark(s)5. Which statements about a DMZ are correct?Select all correct answers.It automatically makes every server secureIt requires carefully controlled rulesIt can reduce direct exposure of the LANIt can isolate public servers from the internal networkFirewall TypesMedium2 mark(s)6. Which device or feature is designed specifically to protect web applications from attacks such as SQL injection?Select one answer.Layer 2 hubWAFDHCP relayNTP serverStateful InspectionMedium2 mark(s)7. A user initiates an outbound HTTPS connection. A stateful firewall permits the reply without a separate inbound allow rule. Why?Select one answer.HTTPS bypasses all firewallsThe server is in a DMZTCP 443 is always trustedThe reply belongs to an established sessionTrap QuestionsHard4 mark(s)8. A VPN tunnel is established, but no traffic passes. The encryption counters remain at zero. What is the most likely area to check first?Select one answer.The firewall hostname lengthThe administrator wallpaperRouting, selectors, and firewall policy for the protected networksPublic DNS root servers onlyNATMedium2 mark(s)9. What does PAT allow?Select one answer.DNS to replace DHCPA switch to become a firewallMany private hosts to share one public IP using different portsOne host to use every VLANTLS InspectionHard5 mark(s)10. Which factors should be assessed before enabling broad TLS inspection?Select all correct answers.Certificate deploymentPerformance capacityApplication exceptionsLegal and privacy requirementsWhether users prefer dark modeSecurity PrinciplesEasy1 mark(s)11. Which principle gives users and systems only the access required for their tasks?Select one answer.Security through obscurityLeast privilegeAny-any accessOpen accessNGFWMedium3 mark(s)12. Which are common NGFW capabilities?Select all correct answers.User-aware policyApplication awarenessIntrusion preventionURL filteringPhysical cable repairFirewall RulesEasy1 mark(s)13. Which firewall action explicitly allows matching traffic?Select one answer.DenyRejectDropPermitFirewall BasicsEasy1 mark(s)14. What is the primary purpose of a network firewall?Select one answer.Create user passwordsRepair damaged cablesIncrease storage capacityControl network traffic according to security rulesTrap QuestionsHard5 mark(s)15. Which conditions can make a firewall rule appear unused even though related traffic exists?Select all correct answers.NAT changes the address used for matchingThe application uses a different port or protocolThe rule name is too shortThe traffic uses a different zoneAn earlier rule matches firstFirewall ArchitectureEasy1 mark(s)16. Which zone is commonly used for public-facing servers that must remain separated from the internal LAN?Select one answer.LoopbackManagement VLAN onlyBroadcast domainDMZBest PracticesMedium3 mark(s)17. Which controls help reduce unnecessary firewall exposure?Select all correct answers.Apply least privilegeUse specific sources and destinationsPermit only required servicesReview unused rulesUse any-any rules by defaultTrap QuestionsHard4 mark(s)18. Why can an any-any allow rule with logging still be dangerous?Select one answer.Logging does not reduce the excessive access grantedLogging converts it into a denyIt protects only UDPAny-any rules cannot match trafficFirewall RulesEasy2 mark(s)19. Which can be basic firewall policy actions?Select all correct answers.AllowRejectLogDefragment diskDenyNGFWMedium2 mark(s)20. Which technology inspects traffic beyond IP addresses and ports to identify applications?Select one answer.ARP onlyDeep packet inspectionBasic repeaterStatic routing onlyFirewall ArchitectureHard4 mark(s)21. Which design best limits damage if an internet-facing DMZ server is compromised?Select one answer.Allow the DMZ to access the entire LANDisable all loggingRestrict DMZ-to-internal access to only essential destinations and servicesPlace the database on the same unrestricted subnetPorts and ProtocolsEasy1 mark(s)22. Which service normally uses TCP port 22?Select one answer.HTTPSNMPSSHDNSVPNMedium3 mark(s)23. Which may be required for a site-to-site VPN to pass application traffic?Select all correct answers.Compatible protected subnetsCorrect routesFirewall policies permitting the trafficMatching encryption parametersOnly a green tunnel iconFirewall RulesMedium2 mark(s)24. Why is rule order important on a first-match firewall?Select one answer.Only the final rule is evaluatedRules are processed randomlyRule order affects cable speedThe first matching rule determines the actionLogging and MonitoringMedium3 mark(s)25. Which are benefits of firewall logging?Select all correct answers.TroubleshootingSecurity monitoringGuaranteed attack preventionAudit evidenceIncident investigationTrap QuestionsMedium2 mark(s)26. A firewall logs traffic as allowed, but the destination server is not listening on the required port. What will happen?Select one answer.The connection is automatically redirectedThe firewall starts the serviceThe connection can still failThe port becomes openNATMedium2 mark(s)27. What is the primary purpose of source NAT for internal users accessing the internet?Select one answer.Assign VLAN tagsEncrypt application dataChange the destination web serverTranslate internal source addressesHigh AvailabilityHard5 mark(s)28. Which can cause stateful firewall session failures in a high-availability design?Select all correct answers.Different policies on cluster membersIdentical system clocksAsymmetric routingUnsynchronized session tablesFailover during active sessionsTrap QuestionsMedium2 mark(s)29. A broad allow-any rule appears above a specific deny rule. What is the likely result?Select one answer.The firewall rebootsBoth rules are ignoredThe deny always winsThe broad rule may permit traffic before the deny is evaluatedTrap QuestionsHard5 mark(s)30. A security team wants to reduce false confidence from 'allow' log entries. Which additional checks are appropriate?Select all correct answers.Confirm the destination application is listeningVerify routing and return pathReview server and application logsAssume the firewall log proves end-to-end successCheck NAT translationFirewall RulesEasy1 mark(s)31. What is an implicit deny rule?Select one answer.A DNS recordA hidden rule that blocks traffic not explicitly permittedA VPN passwordA rule that allows every connectionNATMedium3 mark(s)32. Which statements about NAT are correct?Select all correct answers.NAT automatically encrypts all trafficNAT is not a substitute for a complete security policyNAT changes address informationNAT can hide internal addressingHost FirewallsEasy2 mark(s)33. Which systems may include a built-in host firewall?Select all correct answers.LinuxPassive Ethernet cableWindowsAndroidmacOSFirewall TypesEasy1 mark(s)34. Which firewall commonly protects an individual computer?Select one answer.Load balancer onlyHost-based firewallCore router onlyPatch panelHigh AvailabilityHard4 mark(s)35. A stateful firewall receives the return half of a TCP session on a different cluster member that has no synchronized session state. What may happen?Select one answer.The packet becomes DNS trafficThe client receives a new IPThe firewall automatically converts it to UDPThe return traffic may be dropped as out of stateRule GovernanceHard5 mark(s)36. Which controls are appropriate for reducing firewall rulebase risk?Select all correct answers.Rule recertificationExpiry dates for temporary rulesObject cleanupPermanent any-any access for testingShadowed-rule analysisRouting and FirewallsHard5 mark(s)37. Which observations may indicate asymmetric routing through a stateful firewall?Select all correct answers.DNS records contain aliasesSYN packets are seen on one interface but return packets are absentRouting changes alter session successSessions work when both directions use one pathOut-of-state drops appear on a second firewallTroubleshootingMedium2 mark(s)38. A rule allows TCP 443 to a web server, but users connect by name and receive a name-resolution error. What should be checked first?Select one answer.DNS resolutionNAT table size onlyFirewall fan speedEthernet cable colorPorts and ProtocolsEasy1 mark(s)39. Which protocol and port are normally used for secure web browsing?Select one answer.TCP 80TCP 22TCP 21TCP 443Traffic FlowEasy2 mark(s)40. Which are examples of network traffic direction?Select all correct answers.OutboundClockwiseNorth-southInboundEast-westRouting and FirewallsMedium2 mark(s)41. What is asymmetric routing?Select one answer.Every packet uses the same pathTraffic has no IP addressForward and return traffic follow different pathsA firewall has two passwordsTLS InspectionMedium3 mark(s)42. Which are risks of TLS inspection?Select all correct answers.Application compatibility problemsIt removes the need for access controlPerformance overheadCertificate trust issuesPrivacy concernsFirewall RulesMedium3 mark(s)43. Which settings are commonly required in a firewall rule permitting web traffic to a specific server?Select all correct answers.Correct destination addressCorrect source or source zoneRandom administrator nameAllow actionCorrect service or applicationTLS InspectionMedium2 mark(s)44. What is SSL/TLS inspection used for?Select one answer.Replace all certificates permanentlyInspect otherwise encrypted traffic according to policyIncrease hard-drive spaceAssign IP addressesIDS and IPSMedium2 mark(s)45. What is the main difference between IDS and IPS?Select one answer.IPS only assigns IP addressesThere is no differenceIPS can actively block detected traffic; IDS mainly alertsIDS always encrypts trafficTrap QuestionsMedium3 mark(s)46. Which can explain why traffic is denied even though an allow rule exists?Select all correct answers.The source address does not matchThe destination or service is incorrectThe traffic enters through an unexpected zoneA higher deny rule matches firstThe monitor is turned offFirewall TypesHard5 mark(s)47. Which statements correctly distinguish a WAF from a traditional network firewall?Select all correct answers.A WAF replaces every other security controlBoth may be used togetherA network firewall commonly controls IPs, ports, zones, and sessionsA WAF focuses on HTTP and HTTPS application attacksA WAF can understand web requests at Layer 7Firewall RulesEasy1 mark(s)48. Which firewall action silently discards a packet without notifying the sender?Select one answer.AcceptLogDropRedirectFirewall RulesEasy2 mark(s)49. Which are common firewall rule components?Select all correct answers.DestinationMonitor brightnessSourceActionService or portNGFWHard4 mark(s)50. A firewall policy permits an application by signature but blocks its initial packets before identification completes. Which feature is most relevant?Select one answer.Cable negotiationApplication identification dependency and temporary port-based classificationDNS zone transferHard-drive encryptionPreviousNextSubmit Quiz Related Discover more from SanchitGurukul Subscribe to get the latest posts sent to your email. Type your email… Subscribe