Firewall & IDS/IPS Tuning Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall & IDS/IPS Tuning flashcards as text
A security analyst is reviewing IPS logs and finds high-confidence alerts that were not blocked. What configuration is MOST likely responsible?
Answer: The IPS is operating in detection/passive mode (IDS mode)
When an IPS is configured in passive or detection-only mode, it generates alerts but does not drop or block matching traffic.
Which technique does an attacker use to bypass firewall port filtering by encapsulating malicious traffic inside an allowed protocol such as DNS?
Answer: Protocol tunneling (DNS tunneling)
DNS tunneling encodes malicious data within DNS query/response packets, exploiting the fact that DNS (port 53) is almost universally permitted through firewalls.
When implementing firewall rule cleanup, what is the SAFEST approach to handling rules that have zero hit counts over 90 days?
Answer: Disable and monitor the rules for another 30 days before removal
Disabling and monitoring zero-hit rules for an additional period reduces the risk of accidentally removing rules for infrequent but critical traffic patterns.
An IDS using anomaly-based detection flags a legitimate batch job that runs monthly. What is this an example of?
Answer: A false positive caused by deviation from a learned baseline
Anomaly-based IDS flags deviations from a learned baseline, and infrequent legitimate traffic like monthly batch jobs may not be included in the training window, causing false positives.
Which firewall feature specifically controls which applications can traverse the network regardless of the port they use?
Answer: Application identification (App-ID)
Application identification (App-ID) in NGFW inspects traffic signatures and behavior to identify and enforce policy based on the application, not just the port number.
A company requires that all outbound internet traffic be inspected for data exfiltration. Which placement strategy for an IPS is MOST effective?
Answer: Deploy IPS inline on the internet egress path
Placing the IPS inline on the internet egress path ensures all outbound traffic passes through inspection before leaving the network perimeter.
What is the primary risk of setting IPS detection thresholds too LOW (overly sensitive)?
Answer: Generating excessive false positives that overwhelm analysts and slow response
Overly sensitive thresholds produce high volumes of false positives, causing alert fatigue that can cause analysts to miss real attacks buried in noise.