โ† All CCP Flashcard Decks

Firewall & IDS/IPS Tuning Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Firewall & IDS/IPS Tuning flashcards as text
  1. A security team notices their IDS is generating thousands of alerts per day but analysts can only investigate 50. Which tuning strategy best addresses this alert fatigue?

    Answer: Implement risk-based alert prioritization and suppress known-good traffic baselines

    Risk-based prioritization combined with baselining known-good traffic reduces noise while preserving detection of genuine threats.

  2. Which firewall rule placement principle ensures the most specific rules are evaluated before broader catch-all rules?

    Answer: Most specific rules placed first in the ACL

    Firewalls process rules top-down, so placing the most specific rules first ensures precise matching before broader rules can incorrectly capture traffic.

  3. An IPS is blocking legitimate business traffic to a critical application. What is the FIRST step to resolve this while maintaining security?

    Answer: Create a tuned exception or exclusion for the specific source-destination pair

    Creating a scoped exception for the specific traffic pair resolves the false positive without broadly reducing detection capability.

  4. What does the term 'stateful inspection' refer to in next-generation firewall operation?

    Answer: Tracking the state of active connections to validate packets belong to established sessions

    Stateful inspection tracks connection state tables so only packets that are part of legitimate established sessions are permitted through.

  5. A network IDS deployed in promiscuous mode detects an attack but the malicious traffic has already reached its destination. What does this scenario illustrate?

    Answer: The difference between IDS (detect only) and IPS (inline blocking)

    An IDS in promiscuous mode observes a copy of traffic and can only alert after the fact, whereas an IPS sits inline and can block traffic in real time.

  6. Which metric is MOST useful for evaluating IDS tuning effectiveness over time?

    Answer: False positive rate and mean time to detect (MTTD)

    False positive rate and MTTD together measure both accuracy and speed of detection, making them the best indicators of tuning effectiveness.

  7. A firewall administrator wants to log all denied traffic without impacting performance. Which approach is MOST appropriate?

    Answer: Use asynchronous logging to an external syslog server

    Asynchronous logging offloads log writing to an external syslog server, preventing log I/O from consuming firewall CPU and memory resources.