A Chief Information Security Officer (CISO) wants to: • Prevent employees from downloading malicious content. • Establish controls based on departments and users. • Map internet access for business applications to specific service accounts. • Restrict content based on categorization. Which of the following should the CSO implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Next-generation firewall.
Why this is the answer
A next-generation firewall (NGFW) is the best choice because it offers deep packet inspection, application awareness, and user identity integration. This allows it to prevent malicious content downloads, establish granular controls based on departments and users, and restrict content by categorization. NGFWs can also map internet access to specific service accounts, fulfilling all the CISO's requirements. A web application firewall (WAF) primarily protects web applications from common web-based attacks, not general internet access or content filtering. A secure DNS server helps resolve domain names securely but doesn't provide the comprehensive content filtering or application-level control needed. A jump server is used for secure access to internal networks, not for controlling outbound internet access or content.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed