IS 監査人が、ネットワークの境界セキュリティ設計をレビューしています。次のうち、発信インターネット トラフィックが制御されていることを最も確実に保証するものはどれですか?
正解:C
Explanation
A stateful firewall provides the greatest assurance that outgoing Internet traffic is controlled, as it monitors and filters packets based on their source, destination and connection state. A stateful firewall can prevent unauthorized or malicious traffic from leaving the network, as well as block incoming traffic that does not match an established connection. An intrusion detection system (IDS) can detect and alert on suspicious or anomalous traffic, but it does not block or control it. A security information and event management (SIEM) system can collect and analyze logs and events from various sources, but it does not directly control traffic. A load balancer can distribute traffic among multiple servers, but it does not filter or monitor it. References:
CISA Review Manual (Digital Version), Chapter 6, Section 6.2