Firewall & IDS/IPS Tuning Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall & IDS/IPS Tuning flashcards as text
A zero-day exploit is actively being used against an organization's web server. The IPS has no signature for it. Which control provides the BEST interim protection?
Answer: Applying a virtual patch via WAF custom rules based on the attack behavior
Virtual patching through WAF custom rules can block exploit traffic based on behavioral characteristics before a vendor signature is available.
Which log field is MOST critical to include in firewall deny logs for effective threat hunting?
Answer: Source IP, destination IP, destination port, timestamp, and rule name
Comprehensive deny logs including source/destination IPs, ports, timestamps, and rule names provide the context needed to reconstruct attack patterns during threat hunting.
An organization uses geolocation-based firewall rules to block traffic from high-risk countries. What is a known limitation of this control?
Answer: Attackers can use VPNs, proxies, or compromised hosts in allowed countries to bypass geo-blocking
Geo-blocking is easily bypassed by routing traffic through proxies, VPNs, or compromised systems in permitted geographic regions.
What is 'IPS normalization' and why is it important for evasion prevention?
Answer: Reassembling and normalizing fragmented or malformed packets before inspection to prevent evasion
Normalization reassembles fragmented traffic and corrects protocol anomalies so the IPS inspects the same packet the end host will process, closing fragmentation-based evasion gaps.
A firewall policy review reveals dozens of rules with 'any' as both source and destination. What security principle do these rules violate?
Answer: Least privilege / need-to-know access control
Rules permitting 'any' source to 'any' destination violate the principle of least privilege by granting far broader access than any legitimate business need requires.
When integrating IDS/IPS alerts with a SIEM, which enrichment step MOST improves analyst efficiency during triage?
Answer: Correlating alerts with asset inventory and threat intelligence to add context
Enriching alerts with asset context (e.g., server criticality, owner) and threat intelligence (e.g., known bad IPs) allows analysts to immediately prioritize high-risk events.
Which action should be taken when a firewall rule permits traffic that is no longer required due to a decommissioned system?
Answer: Remove the rule and document the change in the change management system
Removing unused rules and documenting the change maintains the principle of least privilege and ensures the firewall policy reflects current business requirements.