A network architect is evaluating whether to use a stateful inspection firewall or a next-generation firewall (NGFW) for a new deployment. What capability does an NGFW provide that a traditional stateful firewall lacks?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because NGFWs operate at Layer 7, providing application identification (e.g., distinguishing Dropbox from HTTP), user identity integration with directory services, and built-in IPS — capabilities a traditional stateful firewall lacks. A is wrong because stateful inspection firewalls already track TCP session state; this is not a differentiating feature of NGFWs.
Full explanation below image
Full Explanation
B is correct because NGFWs operate at Layer 7, providing application identification (e.g., distinguishing Dropbox from HTTP), user identity integration with directory services, and built-in IPS — capabilities a traditional stateful firewall lacks. A is wrong because stateful inspection firewalls already track TCP session state; this is not a differentiating feature of NGFWs. C is wrong because NAT/PAT is supported by traditional stateful firewalls; it is not an NGFW-specific capability. D is wrong because IP and port-based filtering is basic firewall functionality predating NGFWs.