Q: 11
ON a stateful inspection Firewall where there is no session table, when the status detection
mechanism is enabled and the second packet (CYN+ACK) of 3-way hadshakes reaches the firewall.
Which of the following statements is true?
Options
Discussion
Probably D since with state detection on and no existing session, the firewall relies on its security policy to decide if packets pass. Had something like this in a mock, answer was always about what the policy allows. Agree?
Looks like D, since it depends on what the firewall policy allows even if the session table isn’t there. Not totally sure though.
D , policy rules take effect here since no session table is present. Not sure what Huawei expects on exam, but pretty confident D fits best in this scenario. Someone let me know if they think A is right for any reason.
D
Don’t think A is right here, since no session table gets created on that second packet (SYN+ACK) by default. D is better because it covers the case where the security policy directly permits traffic even without state. Pretty sure that’s what Huawei wants, but open to corrections.
D tbh, trap is A because people always expect session tables by default, but policy check comes first in this case.
D , Huawei's wording always trips me up but really if there's no session table, everything falls back to the permit/deny policy. Saw a similar question before. Anyone disagree?
D , the question tries to trick you into saying session table is involved but with status detection, policy still rules here.
Be respectful. No spam.
Question 11 of 30