Q41Network Intrusion Analysis
How do deep packet inspection and stateful inspection differ?
← → navigate · a answer
Community votes
Discussion · 5
7
Answer D is correct
Deep packet inspection works on layer 7 while statefull inspection works on layer 4, so A and C are incorrect since the methodes don't work on the same layer. B is incorrect because statefull doesn't do anything with contents.
D 3
Selected Answer: D
The main difference between deep packet inspection and stateful inspection is the layer of the network stack where they operate.
Stateful inspection works at the transport layer (Layer 4) of the network stack, and it verifies that the contents of each packet are allowed based on the state of the connection. It does this by tracking the state of each connection, and only allowing packets that match an established connection to pass through. Stateful inspection can provide basic security against network attacks, such as denial-of-service attacks and spoofing attacks.
Deep packet inspection, on the other hand, works at the application layer (Layer 7) of the network stack. It inspects the contents of each packet in detail, looking for specific application-level information such as URLs, keywords, or file types. This lets it identify and block specific types of traffic, such as malware or unwanted applications.
D 2
Selected Answer: D
Packet inspection does not verify connections, it inspects them, that's why D is correct and B is not.
1
D IS CORRECT LAYER 7 IS THE SITE TO SITE THAT PROVIDES THE APPLICATION CONNECTION
STATEFUL /LAYER 4
1
D. Deep packet inspection gives visibility on Layer 7 and stateful inspection gives visibility on Layer 4