FUNDAMENTALS OF COMPUTER

COMPUTER THREATS SECURITY

WHAT IS A FIREWALL IN NETWORK SECURITY

Question [CLICK ON ANY CHOICE TO KNOW THE RIGHT ANSWER]
You are monitoring network traffic on your network. You see a large amount of traffic between a Windows workstation and a Windows server on the following ports:* 137* 138* 139 What is the source of this network traffic?
A
The workstation is using NetBIOS to access shared resources on the server.
B
A denial of service (DoS) attack on the server is in progress.
C
The workstation is accessing messages from the email service on the server.
D
The workstation is synchronizing its local time with the time on the server.
Explanation: 

Detailed explanation-1: -Port 139 is utilized by NetBIOS Session service. Enabling NetBIOS services provide access to shared resources like files and printers not only to your network computers but also to anyone across the internet. Therefore it is advisable to block port 139 in the Firewall.

Detailed explanation-2: -Port 135 is used for RPC client-server communication; ports 139 and 445 are used for authentication and file sharing. UDP ports 137 and 138 are used for local NetBIOS browser, naming, and lookup functions.

Detailed explanation-3: -Port 445 is a traditional Microsoft networking port with tie-ins to the original NetBIOS service found in earlier versions of Windows OSes. Today, port 445 is used by Microsoft Directory Services for Active Directory (AD) and for the Server Message Block (SMB) protocol over TCP/IP.

Detailed explanation-4: -A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization’s previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

There is 1 question to complete.