AP Cybersecurity Unit 3 Lesson 3 Quiz

Unit 3 • 3.3 • Quiz

Lesson 3.3 Quiz: Firewalls & Packet Filtering

5 questions — Demonstrate your understanding of firewall concepts

Score: 0 / 0 Answer each question, then check your score below
Scenario Organization
NovaTech Solutions

NovaTech Solutions is a 300-employee SaaS company hosting its product on AWS. The security team manages a multi-tier firewall architecture: a perimeter NGFW, internal segmentation firewalls between production and development environments, and a WAF protecting customer-facing APIs.

Q1 Firewall Architecture
NovaTech’s WAF blocks a SQL injection attempt targeting the customer API. The perimeter NGFW did not flag this traffic. Which of the following BEST explains why the NGFW missed the attack but the WAF caught it?
Q2 Stateful Inspection
NovaTech’s stateful firewall logs show that a packet was automatically allowed with the notation “ESTABLISHED.” Which of the following BEST describes what this means?
Q3 Rule Misconfiguration
A developer reports they cannot SSH (port 22) into the staging server from the development subnet. The firewall rules are:

Rule 1: DENY TCP from ANY to ANY on port 22
Rule 2: ALLOW TCP from 10.20.0.0/16 to 10.30.0.5 on port 22
Rule 3: DENY ALL

What is the MOST likely cause?
Q4 Firewall Evasion
An attacker tunnels malicious traffic inside DNS queries (port 53) to bypass NovaTech’s firewall, which allows outbound DNS. This evasion technique succeeds because:
Q5 Defense in Depth
NovaTech’s architecture places a WAF in front of the API servers, behind the perimeter NGFW. Which of the following is NOT a valid reason for deploying both a WAF and an NGFW rather than relying on the NGFW alone?
Questions Correct
Course Hub → Course Hub
AP Cybersecurity Unit 3 • 3.3 • Quiz | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]