In this thread, you will discuss the Network Security Strategies and Firewall Rule Philosophies.
Assume you are a network administrator. Your internal network has application servers that are accessed by inbound traffic from the Internet. You are considering several strategies. The strategy you select should provide significant control over user access. You must also ensure that all data passing into the internal network is properly evaluated before access is granted. Integrity of data is the top priority.
Answer the following question:
Which firewall security strategy would be the best solution for the scenario? Why?
Two main philosophies or security stances govern the use of firewall rules.
Deny by default/allow by exception assumes that all traffic is potentially malicious or at least unwanted or unauthorized.
Everything is prohibited by default. As benign, desired, and authorized traffic is identified, an exception rule grants it access to the network.
Allow by default/deny by exception assumes that most traffic is benign. Everything is allowed by default. As malicious, unwanted, or unauthorized traffic is identified, an exception rule blocks it.
Most security experts agree that deny by default/allow by exception is the more secure stance to adopt.
Answer the following question:
When would you use allow by default/deny by exception? Provide a rationale for your answer.
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
