WorksheetsSonicWall Firewall Features Quiz
Total questions: 155
Worksheet time: 1hrs 23mins
Which of the following advanced threat protection features are enabled by SonicOS?
Intrusion Detection System (IDS)
Sandboxing
Data Loss Prevention (DLP)
SSL+SSH+TLS decryption and inspection
How many auto-scheduled cloud configuration backups are supported per firmware version in a SonicWall firewall?
1 per firmware
2 per firmware
3 per firmware
Unlimited
In SonicOS, which panel of the management interface is used to define password restrictions?
System > Administration
Manage > Appliance > Base Settings > Login Security
Security > Authentication
Users > Password Management
Which of the following is a built-in firewall system schedule in SonicWall?
Business Hours
Work Hours
Weekend Mode
Night Shift
Which setting, when enabled, requires a strong password to avoid potential security vulnerabilities?
Enable SSH Management
Allow HTTPS on this WAN interface
Enable SNMP Monitoring
Enable VPN Access
The HTTP-based management option in SonicOS is disabled by default.
True
False
SonicWall firewalls can interoperate with any X.509v3 certificates issued by third-party CA authorities.
True
False
Which of the following is the default public server type in SonicWall?
Web Server
FTP Server
Terminal Services Server
Mail Server
Which local network is selected by default in the firewall?
LAN Subnets
Firewall Subnets
VPN Zones
DMZ Subnets
Which of the following network applications are available by default in the App Rule Guide to create policies?
SMTP
FTP File Server
Web Access
All of the above
Which Advanced Interface setting allows initial packets or response packets to pass through other interfaces?
Enable Asymmetric Route Support
Packet Filtering
Stateful Inspection
NAT Passthrough
What is the default IP version setting for sending or receiving DNS Proxy packets between the firewall and DNS servers?
IPv6 to IPv4
IPv4 to IPv6
IPv4 to IPv4
IPv6 to IPv6
Which option is a messaging protocol used to build a cache of dynamic entries for IPv6 devices?
Address Resolution Protocol (ARP)
Neighbor Discovery
Dynamic Host Configuration Protocol (DHCP)
Internet Control Message Protocol (ICMP)
Which MAC-IP Anti-Spoof network setting prevents the spoofing of packets by a bad device or unwanted ARP packets?
ARP Filtering
MAC Binding
ARP Lock
Anti-Spoofing Mode
What type of information does the DHCP server help distribute to network clients?
IP Addresses
Gateway Addresses
DNS Server Settings
Radius Server Settings
Which of the following DDNS providers are supported in SonicOS?
changeIP.com
dyn.com
no-ip.net
All of the above
Which user authentication method provides centralized authentication and authorization?
LDAP
RADIUS
Local Users
TACACS+
Which authentication method is recommended for a relatively smaller number of users?
RADIUS
SSO Agent
Local Users
Active Directory
Which type of SSO method identifies users based on the workstation IP address?
Kerberos
LDAP Proxy
SSO Agent
RADIUS Accounting
Which of the following types of privileges can an admin be assigned to?
Full privileges (config or non-config)
Read-Only Access
Custom Role-Based Access
All of the above
What type of specific and advanced threat protection features are enabled by SonicOS?
Intrusion Detection System (IDS)
Sandboxing
Data Loss Prevention (DLP)
SSL + SSH + TLS decryption and inspection
How many auto-scheduled cloud configuration backups are supported for each firmware version in the SonicWall firewall?
1 per firmware
2 per firmware
3 per firmware
Unlimited
Which panel of the SonicOS management interface is used to define password restrictions?
System > Administration
Manage > Appliance > Base Settings > Login Security
Security > Authentication
Users > Password Management
The HTTP-based management option in SonicOS is disabled by default.
True
False
SonicWall firewalls can interoperate with any X.509v3 certificates issued by third-party CA authorities.
True
False
Which of the following is a built-in firewall system schedule?
Business Hours
Work Hours
Weekend Mode
Night Shift
Which setting, when enabled, requires a strong password to avoid potential security vulnerabilities?
Enable SSH Management
Allow HTTPS on this WAN interface
Enable SNMP Monitoring
Enable VPN Access
What is the default public server type in SonicWall?
Web Server
FTP Server
Terminal Services Server
Mail Server
Which local network is selected by default in the firewall?
LAN Subnets
Firewall Subnets
VPN Zones
DMZ Subnets
Which of the following network applications are available by default in the App Rule Guide to create policies?
SMTP
FTP File Server
Web Access
All of the above
Which Advanced Interface setting allows initial packets or response packets to pass through other interfaces?
Asymmetric Routing
Packet Filtering
Stateful Inspection
NAT Passthrough
What is the default IP version setting for sending or receiving DNS Proxy packets between the firewall and DNS servers?
IPv6 to IPv4
IPv4 to IPv6
IPv4 to IPv4
IPv6 to IPv6
Which option is a messaging protocol used to build a cache of dynamic entries for IPv6 devices?
Address Resolution Protocol (ARP)
Neighbor Discovery
Dynamic Host Configuration Protocol (DHCP)
Internet Control Message Protocol (ICMP)
Which MAC-IP Anti-Spoof network setting prevents spoofing of egress packets by a bad device or unwanted ARP packets?
ARP Filtering
MAC Binding
ARP Lock
Anti-Spoofing Mode
What type of information does the DHCP server help distribute to network clients?
IP Addresses
Gateway Addresses
DNS Server Settings
All of the above
Which of the following DDNS providers are supported in SonicOS?
changeIP.com
dyn.com
no-ip.net
All of the above
Which user authentication method provides centralized authentication and authorization?
LDAP
RADIUS
Local Users
TACACS+
Which authentication method is recommended for a relatively smaller number of users?
RADIUS
SSO Agent
Local Users
Active Directory
Which type of SSO method identifies users based on the workstation IP address?
Kerberos
LDAP Proxy
SSO Agent
RADIUS Accounting
Which of the following types of privileges can an admin be assigned to?
Full privileges (config or non-config)
Read-Only Access
Custom Role-Based Access
All of the above
The default guest profile cannot be deleted.
True
False
Which setting is enabled to prioritize VPN traffic over static routes?
Enable Route Precedence
Allow VPN path to take precedence
Static Route Priority
VPN Traffic Control
Which option is a common mechanism for preventing routing loops?
OSPF Redistribution
Route Injection
Split Horizon
BGP Peering
Which feature is used to configure event log attributes globally, using flexible match conditions?
Go to CONFIGURE Log (on the right)
Global Logging Settings
Log Event Manager
Match-Based Logging
Which feature, located in the left panel, provides information about the applied filters?
Event Log Summary
Filter Logic (bottom of the page)
Filter Debug Panel
Packet Inspection Log
Which client CF event object is assigned a higher priority level?
Client CF access without agent (CRITICAL)
Client CF access with agent (CRITICAL)
Client CF Generic
Default CF Event
Which logging feature is used to create a predefined email notification with a defined subject?
Notification Rules
Event Triggering
Automation
Alert Forwarding
What are two probe methods that can be used for logical probes? (Select all that apply)
UDP
Ping
TCP
ICMP
Which action object is used to throttle the traffic when a website from a category is accessed?
Content Filtering
Bandwidth Management (BWM)
App Control
DPI-SSL Inspection
Which of the following Address Object types is selected by default in the firewall?
Host
Network
Range
Zone
Which diagnostic utility on the SonicWall firewall allows you to look at the contents of IP packets traversing the firewall?
Log Analyzer
Packet Monitor
Connection Tracker
DPI Monitor
Where is the real-time data on the Dashboard compiled and summarized from?
Manage >> AppFlow Settings
Reports >> Logs
System >> Diagnostics
Network >> Traffic Monitor
What type of information is displayed on the Live Monitor panel? (Select all that apply)
Applications
Ingress/Egress Bandwidth
Ingress/Egress Packet Rate
Multi-Core Monitor
Ingress/Egress Packet Size
Which file types can be used to export logs? (Select all that apply)
CSV
TEXT
What is the default timeout setting for administrator inactivity?
5 Minutes
10 Minutes
15 Minutes
30 Minutes
What type of encoding format is supported when importing an end-user certificate with a private key?
DER
PEM
PKCS#12
X.509
Which SonicOS GUI option is used to create a snapshot of the current system state?
Save Configuration
Create Backup
Export Settings
Snapshot Generator
Which interface is used by SonicOS as the backup heartbeat link for HA (High Availability)?
X0
X1
X2
X3
The firewall snapshot section displays the percentage of encrypted traffic flowing through the firewall.
True
False
Which setting is used to turn on the CFS Security Service?
Manage >> Security Config >> Content Filter >> Select "SonicWall CFS" for content Filter Type
Manage >> Firewall Settings >> Enable CFS Security
Network >> Security Services >> Enable Content Filtering
AppFlow >> Content Security >> Enable CFS
Which Security Configuration menu option is used to enable client DPI-SSL?
Manage >> Security Config >> Decryption Services >> General Tab, then check the box "Enable SSL Client Inspection"
Network >> DPI-SSL >> Enable DPI-SSL for all traffic
Security Services >> SSL Configuration >> Enable DPI-SSL
Firewall >> DPI Settings >> Enable SSL Decryption
Which of the following security features is enabled along with DPI-SSL? (Select all that apply)
Intrusion Prevention
Gateway Anti-Virus
Gateway Anti-Spyware
Application Firewall
Content Filter
Which Match Object property will control what type of policy it can be used in?
Policy Type
Rule Condition
Match Object Type
Filter Category
What are the key components of a CFS policy? (Select all that apply)
Block
Passphrase (Authenticate)
Confirm
Bandwidth Management
Which Logs panel depicts the EICAR test virus file download?
Investigate >> Logs >> Firewall Logs
Investigate >> Logs >> Event Logs
Security Services >> Logs >> Threat Reports
Monitor >> Security Incidents
A Site-to-Site VPN can allow simultaneous access to multiple remote servers. (True / False)
True
False
Which statement about SonicWall Gateway Anti-Virus service is correct?
It inspects all traffic that traverses the SonicWall Gateway
It inspects all web application protocols, but ignores TCP streams
It requires file-size limitations for scanning
It does not support compressed traffic scanning
Which of the following sentences is correct about High Availability (HA) configuration?
High Availability does not support Portshield interfaces and Native Bridge mode
HA supports all network interface configurations
HA can be configured without additional hardware
HA is enabled by default
What type of NAT policies does a Public Server wizard create? (Select all that apply)
Inbound NAT Policies
Outbound NAT Policies
Loopback NAT Policies
Dynamic NAT Policies
Which of the following is included in the output of a network probe? (Select all that apply)
Probe Target
Name
Probe Type
Local IP
Gateway
Which diagnostic utility on the SonicWall firewall allows you to look at the contents of IP packets traversing the firewall?
Log Analyzer
Packet Monitor
Connection Tracker
DPI Monitor
What are the default Network Zones in SonicWall? (Select all that apply)
MULTICAST
VPN
LAN
DMZ
WAN
What are the default rules in SonicWall? (Select all that apply)
LAN to WAN: Allow All
WAN to LAN: Deny All
LAN to LAN: Allow All
WAN to WAN: Allow All
DMZ to LAN/WAN: Deny All
Advanced Threat Protection is enabled by default.
True
False
What is the default IP address of a SonicWall appliance?
192.168.1.1
192.168.168.168
10.0.0.1
172.16.1.1
App Rules are enabled by default.
True
False
What is the default WAN interface in SonicWall?
X0
X1
X2
X3
What is the default LAN interface in SonicWall?
X0
X1
X2
X3
What is the default probing address for failover in SonicWall?
google.com
dns.sonicwall.com
responder.global.sonicwall.com
8.8.8.8
What are the default Security Types in SonicWall? (Select all that apply)
Trusted
Public
Untrusted
SSLVPN
Encrypted
What formats are available for exporting Packet Monitor results? (Select all that apply)
Libpcap
Pcap
Text
HTML
AppData
What is visible on the Appliance Health Overview window? (Select all that apply)
Top Spyware
Top Viruses
Top Users
Top Intrusions
Top Applications
A customer has an established base of GVC VPN users with a WAN GroupVPN policy configured. The customer wants to implement SSL VPN users. Why must the GVC VPN users be converted to SSL VPN users?
The SonicWall appliance does not support both types of VPN users simultaneously
GVC VPN is outdated and no longer supported
SSL VPN provides better performance than GVC VPN
GVC VPN only works with specific firewall models
SSL VPN eliminates the need for remote access authentication. (True / False)
True
False
Which of the following correctly describes how a bandwidth management rule works?
Can only be configured for outbound traffic from the firewall
Applies only to individual VPN Security Associations
Can be configured for all VPN traffic
Applies only to inbound traffic from the WAN
What are the benefits provided by a VPN? (Select all that apply)
Securely connects distributed networks together
Prevents denial-of-service attacks on remote connections
Enables a remote connection to the LAN via the Internet
Assures remote clients have up-to-date antivirus software
Provides data confidentiality and sender authentication
What benefits are provided by a VPN? (Select all that apply)
Reporting
Increased capacity
Scalability
Encryption
Security
Which of the following is the most basic firewall technology?
Single Firewall
Next-Generation Firewall (NGFW)
Deep Packet Inspection
Packet Filtering
The default firewall access rule allows all communication from the LAN to the Internet.
True
False
What are two advantages of using multiple firewalls?
Protects restricted special resources
Allows all network segments free access to other segments
Helps protect entire departments
Reduces firewall configuration complexity
What is the purpose of a security policy?
To authenticate users and devices before granting network access
To monitor network security and configure firewalls to prevent misuse
To make it more difficult for hackers to locate a security hole in a network
To describe how a company approaches security, including rules of conduct and acceptable risk
What question would you ask to get specific information on user restrictions?
What kinds of network traffic will you allow?
Will the computers be locked away from the public, or will they have access to the hardware?
Will users be allowed to log in at any time, from any location, to any machine?
Who should be allowed to access your services?
Content Filtering Services applies to which of the following traffic protocols?
HTTPS
FTP
HTTP
Email attachments
If the appliance loses connection to the SonicWall site rating library, what actions can it take? (Select all that apply)
CFS blocks all web traffic (based on configuration)
CFS continues to operate using the last ratings seen
CFS allows all web traffic (based on configuration)
CFS must use its internal logic to identify which traffic to block
With SonicWall CFS, network administrators have a flexible tool to provide comprehensive filtering based on which of the following? (Select all that apply)
Time of day
Allowed domain designations
SMTP
Keywords
Forbidden domain designations
The default CFS policy when assigned "Via Users and Zones Screens" should be the most restrictive. (True / False)
True
False
The SonicWall Log can be exported in the following formats: (Select all that apply)
Log View
Team-separated value (CSV)
Comma-separated value (CSV)
Tab Delimited
Plain text
What options are used to preempt an administrator logged into the firewall? (Select all that apply)
Log Out
Drop into Non-config Mode
Reset Firewall
Disable Admin Access
Which of the following network applications are available by default in the APP Rule Guide to create policies? (Select all that apply)
FTP File Transfer
SMTP Email
Web Access
POP3 Email
The default Guest Profile cannot be deleted.
True
False
What type of mapping does ARP (Address Resolution Protocol) enable?
IP address to MAC address
MAC address to IP address
Domain name to IP address
IP address to domain name
Which firewall network setting allows the current state of the DHCP leases in the network to be periodically written to Flash?
DHCP Lease Scavenging
DHCP Lease Synchronization
Enable DHCP Server Persistence
DHCP Binding
Which advanced network interface setting on the SonicWall NSv firewall allows initial packets or response packets to pass through other interfaces?
Path MTU Discovery
Proxy ARP
Enable Asymmetric Route Support
IP Spoof Detection
Which of the following DDNS Providers are supported in SonicOS?
DynDNS
No-IP
Google DNS
ChangeIP
The SonicOS NSv scheme of interface addressing works in conjunction with address objects, service objects, and network zones.
True
False
The Public Server guide assigns the server automatically to the zone to which its IP address belongs
True
False
When configuring a Site-to-Site policy, the Local Network option must match the Destination Network on the other side of the tunnel, in order to avoid tunnel negotiation errors or even a total failure.
True
False
Which of the following is the default public server type?
FTP Server
VPN Server
Web Server
Mail Server
What options are used to preempt an administrator logged into the firewall?
Log out
Simultaneous configuration
Drop into Non-Config mode
Deny access
What are some of the key features of SonicWall Next-Gen firewalls?
Network Segmentation,
Flexible Deployment
Application intelligence
Control
What are some of the key features of SonicOS 7 architecture?
Advanced protection against encrypted threats,
Simplified integration
Easy zero-touch deployment
TLS 1.3
Select two best practices that should be implemented before updating the firewall firmware.
Download a settings file locally
Use the create backup option built into the firewall
Create a HA pair
Reboot the firewall
The default mode of NSv is
Transparent Mode
Policy Mode
Layer 2 Bridge Mode
NAT Mode
Static routes, by default, take precedence over VPN traffic.
True
False
Routing applies to packets as they exit from the firewall
True
False
Which of the following are included in the output of a network monitor?
Probe Type
Probe Target,
IP Version,
Interface
CPU Usage
What type of intermediate traffic is monitored by the Packet Monitor?
Encrypted Packets
Multicast packets that are replicated
IP Helper-generated
Encrypted VPN traffic payloads
Which of the following are available in with the Basic Capture Client License? (Select all that apply)
Integration with Capture Security Center
Role-based access control
Device Control & Network Access Control
Windows Server Support
Application Vulnerability Intelligence helps catalog every application on each protected endpoint.
True
False
Which packet status types are indicated by the Packet Monitor?
Dropped
Forwarded
Encrypted
Consumed
NSM on prem offers large scale centralized management of SonicWall Gen 7 devices only?
True
False
Export formats for snapshot of Packet Monitor include:
HTML
CSV
PCAP
Plain Text
Keep Alive should be enabled on the firewall with the most processing overhead
True
False
What is the default session time an administrator can be logged into the firewall
30 min
15 min
5 min
10 min
What user authentication should be used for groups with more than 1000 users and provides an extra layer of security?
Radius
LDAP
Local Users
TLS
The SonicWall Administrator has modified the default LAN > WAN access rule from "allow" to "deny", blocking all outbound WAN traffic. Which of the following statements is true?
LAN users can still access the internet because stateful packet inspection allows return traffic.
LAN users cannot access the internet, but the firewall can still register with mysonicwall.com and update UTM signatures.
The firewall will block all outbound traffic, including its own updates and registrations.
LAN users can still access the internet, but only over non-standard ports.
When creating a site to site VPN, the policy type should be set to?
Tunnel Interface
Site to Site
IKE using Preshared Secret
Multiple Site
When creating a Route-Based VPN in SonicOS 7, the policy type should be set to?
IPSec Keying Mode
Tunnel Interface
Main Mode
Site-to-Site
Which protocol provides separate Authentication, Authorization, and Accounting (AAA) services?
Radius +
TACACS +
LDAP
Kerberos
The NSM Closed Network Support feature is ideal for customers who run:
Public cloud-based infrastructures
One or more private networks that are completely shut off from the outside environment
Small office/home office (SOHO) networks
Hybrid Clouds
NSM On-Prem requires a separate license for the reporting and analytics features
True
False
Setting the Event Priority level lower than the Logging Level will cause those events to be filtered out from Event Logs
True
False
If the Logging Level Filter is defined as Error, which of the following alert messages will also be displayed in the results?
Emergency
Informational
Critical
Alert
Warning
Advanced routing is enabled by default?
True
False
Which of the following variables are used to configure static routes to forward traffic?
Interfaces
Services
Source MAC address
Destination MAC address
Which protocols are supported by the Advanced Routing mode of SonicWall NSv?
RIP
OSPFv3
EIGRP
Bridge Mode
Who among the following can manage Guest Accounts and Sessions
Guest Administrators
Limited Administrator
Firewall Operator
JIT Administrator
Which of the following are the default user groups to which a new user is automatically added in a SonicWall firewall?
Trusted Users
Guest Services
Administrators
SSLVPN Users
Everyone
Which user authentication methods are available in a SonicWall NSv?
Local User
RADIUS
TACACS +
LDAP
SSO
A Site-to-Site VPN can allow simultaneous access to multiples remote servers
tRUE
fALSE
Which of the following sentences is correct about HA configuration?
HA can be configured without additional hardware
HA is enabled by default
High Availability cannot be configured while there are ports participating in PortShield
HA supports all network interface configurations
Enhanced Security Mode enables
Maximum security by inspecting all content with any threat probability - High, Medium or Low
Maximum security by inspecting all content with any threat probability - High or Medium.
Maximum security by inspecting all content with any defined threat level.
Maximum security by inspecting all content with a Low threat probability
A major advantage of a route based VPN is
It provides flexibility on how traffic is routed
It requires less configuration than policy-based VPNs
It does not support multiple subnets
It eliminates the need for a VPN gateway
Before registering a firewall, a MySonicWall account needs to be created
True
False
Select the two methods used to register the SonicWall appliance
Manual Registration via MySonicWall
Through the SonicOS web management interface
Offline Registration via USB Drive
Command Line Registration using SSH
Enabling HTTPS management of the WAN interface is considered a best practice
True
False
The interface through which the firewall is managed can be disabled
True
False
A custom service object cannot be created
True
False
Which object represents a cluster of multiple services for security filtering?
Security Policy
App Rule
Service Group
Address Object
In order for SonicWall1's Deep Packet Inspection engine to provide protection, where must GAV, IPS, and Gateway Anti-Spyware be enable?
Security Services
Zones
Firewall Access Rules
Interface settings
DPI-SSL settings
What is the default user authentication method in the firewall?
Local Users
Radius
LDAP
SAML
What port number is used for SSO?
443
3389
2258
639
What type of encoding format includes a private key inside?
PEM
CER
PKCS#12
DER
In SonicWall, what is the maximum number of entries that can be configured for Split DNS?
5
10
50
32
What is the purpose of maintaining an ARP cache in the firewall?
minimize the broadcast traffic,
store and reuse the earlier ARP information
Enhances the performance of routing by storing IP routing tables
Allows the firewall to track the availability of remote network resources
