Which next-generation firewall mode actively blocks flows traversing the firewall?
Choose an answer
Tap an option to check your answer.
Correct answer: inline.
Why this is the answer
The correct answer is inline because an inline firewall is placed directly in the data path, allowing it to actively inspect and block traffic as it traverses the network. This deployment mode is essential for actively enforcing security policies and preventing threats. Tap mode (also known as sniffing orSPAN) involves sending a copy of the traffic to the firewall for analysis, but the firewall is not in the data path and cannot block traffic. Passive mode is similar to tap mode, where the firewall monitors traffic without actively interfering with it. Inline tap is not a standard, distinct operational mode for next-generation firewalls; it's a combination that doesn't represent an active blocking capability in the way "inline" does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed