Application firewalls and network firewalls are preventive security controls because they are designed to stop unauthorized or malicious traffic before it reaches protected systems. A network firewall enforces traffic rules based on factors such as source, destination, protocol, port, and application. An application firewall, such as a WAF, can block application-layer attacks like SQL injection, cross-site scripting, and malicious HTTP requests. Deterrent controls discourage behavior but do not directly block traffic. Administrative controls are policies, procedures, standards, or governance mechanisms. Physical controls protect facilities, equipment, and physical access. Since firewalls actively prevent unwanted communications and reduce the likelihood of compromise, the correct control type is preventive.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit