Which two features are available only in next-generation firewalls?

Which two features are available only in next-generation firewalls? (Choose two.)

  1. application awareness Source Reference Answer
  2. packet filtering
  3. stateful inspection
  4. deep packet inspection Source Reference Answer
  5. virtual private network

Community Votes

AD
100%

100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to differentiate NGFW capabilities from traditional firewall features, with the common trap being confusing stateful inspection (a traditional feature) with deep packet inspection (an NGFW feature).

Next-generation firewalls (NGFWs) introduce application awareness and deep packet inspection (DPI) as distinguishing features beyond traditional firewalls. Community consensus strongly confirms that options A and D are the correct answers, as these capabilities allow NGFWs to identify and control traffic at the application layer.

Many candidates incorrectly choose C (stateful inspection) because it sounds advanced, but stateful inspection has been a core feature of traditional firewalls since the 1990s and is not exclusive to NGFWs.

Community Discussion (3 comments)

supershysherlock 👍 6 Selected: AD
A. Application awareness: NGFWs have the ability to identify and control applications running over the network, allowing for more granular control and security policies based on specific applications. D. Deep packet inspection (DPI): NGFWs perform DPI to analyze the contents of packets beyond their headers, allowing them to detect and block advanced threats, malware, and other suspicious activities within the network traffic. Packet filtering (B), stateful inspection (C), and virtual private network (E) capabilities are not exclusive to NGFWs and can also be found in traditional firewalls.
chiacche 👍 1 Selected: AD
NGFWs have the ability to identify and control applications running on the network, allowing for more granular control and security policies based on specific applications. -> traditional firewalls typically filter traffic only based on ports or protocols. Deep packet inspection (DPI) is a feature unique to NGFWs, whereas traditional firewalls mostly inspect packet headers.
Mizuchan 👍 2 Selected: AD
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Application awareness (A) allows NGFWs to identify and control traffic based on the specific application generating it, rather than just port or protocol numbers. Deep packet inspection (D) enables the firewall to examine the actual payload of packets, not just headers, to detect malware, enforce policies, and identify applications hiding on non-standard ports. These two features are the hallmark capabilities that define a next-generation firewall according to industry standards and Cisco documentation.

Why the Other Options Are Wrong

Packet filtering (B) is the most basic form of firewall functionality, operating at Layer 3/4 and examining only source/destination IPs and ports — it is a traditional firewall feature. Stateful inspection (C) tracks the state of active connections and has been standard in firewalls since the mid-1990s, making it a traditional rather than next-generation feature. Virtual private network (E) support is widely available on traditional firewalls, routers, and dedicated VPN appliances, so it is not exclusive to NGFWs.

Community Comment Notes

Community members overwhelmingly agree on AD, with comment [1] clearly explaining that application awareness enables granular control based on specific applications. Comment [2] reinforces this by noting that traditional firewalls filter only by ports or protocols, while DPI is unique to NGFWs. One dissenting comment [3] suggested C, but this reflects the common misconception that stateful inspection is an NGFW-exclusive feature.

Official Reference

Exam Strategy

When asked about NGFW-exclusive features, focus on capabilities that go beyond Layer 3/4 inspection. Remember that application awareness and deep packet inspection are the defining characteristics of NGFWs, while packet filtering, stateful inspection, and VPN are legacy features available on traditional firewalls.

Related Analysis

Practice All 350-401 Questions

Access 218 questions with complete answers and detailed explanations.

View Full 350-401 Practice Test →

← Back to 350-401 Study Guide