Which two features are available only in next-generation firewalls?
Which two features are available only in next-generation firewalls? (Choose two.)
Community Votes
100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to differentiate NGFW capabilities from traditional firewall features, with the common trap being confusing stateful inspection (a traditional feature) with deep packet inspection (an NGFW feature).
Next-generation firewalls (NGFWs) introduce application awareness and deep packet inspection (DPI) as distinguishing features beyond traditional firewalls. Community consensus strongly confirms that options A and D are the correct answers, as these capabilities allow NGFWs to identify and control traffic at the application layer.
Many candidates incorrectly choose C (stateful inspection) because it sounds advanced, but stateful inspection has been a core feature of traditional firewalls since the 1990s and is not exclusive to NGFWs.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Application awareness (A) allows NGFWs to identify and control traffic based on the specific application generating it, rather than just port or protocol numbers. Deep packet inspection (D) enables the firewall to examine the actual payload of packets, not just headers, to detect malware, enforce policies, and identify applications hiding on non-standard ports. These two features are the hallmark capabilities that define a next-generation firewall according to industry standards and Cisco documentation.Why the Other Options Are Wrong
Packet filtering (B) is the most basic form of firewall functionality, operating at Layer 3/4 and examining only source/destination IPs and ports — it is a traditional firewall feature. Stateful inspection (C) tracks the state of active connections and has been standard in firewalls since the mid-1990s, making it a traditional rather than next-generation feature. Virtual private network (E) support is widely available on traditional firewalls, routers, and dedicated VPN appliances, so it is not exclusive to NGFWs.Community Comment Notes
Community members overwhelmingly agree on AD, with comment [1] clearly explaining that application awareness enables granular control based on specific applications. Comment [2] reinforces this by noting that traditional firewalls filter only by ports or protocols, while DPI is unique to NGFWs. One dissenting comment [3] suggested C, but this reflects the common misconception that stateful inspection is an NGFW-exclusive feature.Official Reference
Exam Strategy
When asked about NGFW-exclusive features, focus on capabilities that go beyond Layer 3/4 inspection. Remember that application awareness and deep packet inspection are the defining characteristics of NGFWs, while packet filtering, stateful inspection, and VPN are legacy features available on traditional firewalls.
Related Analysis
Practice All 350-401 Questions
Access 218 questions with complete answers and detailed explanations.
View Full 350-401 Practice Test →