A small business owner asks a network consultant whether they need a separate firewall appliance or whether the built-in firewall feature on their ISP-provided modem/router combo is sufficient for their 10-employee office.
What is the MOST important factor the consultant should raise about ISP-provided modem/router firewalls compared to a dedicated business firewall appliance?
- A.ISP-provided devices always use weaker encryption standards that do not meet business compliance requirements; certificate validation checks only the expiry date; the issuer chain is informational. A DMZ places internal file servers outside both firewalls for faster access
- B.ISP-provided devices often have delayed or discontinued firmware updates, limited logging and visibility, no centralized management, and fewer security features compared to dedicated business firewall appliances designed for ongoing enterprise security management
- C.ISP-provided devices cannot perform NAT, which is required to protect internal IP addresses from internet exposure; DNS amplification relies on TCP handshakes completing faster at open resolvers. A VPN concentrator terminates tunnels by decrypting traffic at the ISP's edge, outside the corporate boundary