The CIRT is reviewing an incident that involved a human resources recruiter exfiltrating sensitive company data. The CIRT found that the recruiter was able to use HTTP over port 53 to upload documents to a web server. Which of the following security infrastructure devices could have identified and blocked this activity?
Choose an answer
Tap an option to check your answer.
Correct answer: NGFW utilizing application inspection.
Why this is the answer
An NGFW (Next-Generation Firewall) with application inspection capabilities can identify and block unauthorized application usage, even if it attempts to masquerade on non-standard ports. In this scenario, the NGFW could detect that HTTP traffic was being used over port 53 (typically DNS) and, based on policy, block the exfiltration attempt. A WAF (Web Application Firewall) primarily protects web applications from attacks, not general network traffic or protocol misuse like this. A UTM (Unified Threat Management) device with a threat feed might identify known malicious IPs or domains, but not necessarily detect an application misusing a port unless it also incorporates NGFW-like application inspection. SD-WAN (Software-Defined Wide Area Network) focuses on optimizing network traffic and connectivity, not deep packet inspection for application-layer threats.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed