Network Perimeter Defense Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Perimeter Defense flashcards as text
A company wants to prevent employees from uploading sensitive files to personal cloud storage services. Which perimeter control is MOST effective?
Answer: SSL/TLS inspection combined with a data loss prevention (DLP) proxy
SSL/TLS inspection decrypts HTTPS traffic at the proxy, enabling DLP policies to inspect content and block unauthorized uploads to cloud storage.
What does the principle of 'implicit deny' mean in firewall rule design?
Answer: Traffic not matched by any explicit rule is denied by default
Implicit deny means that any traffic not explicitly permitted by a firewall rule is automatically blocked, enforcing a default-deny security posture.
An attacker sends packets with the source IP set to an internal address from outside the network. What firewall technique prevents this?
Answer: Ingress filtering with RFC 3704 uRPF (Unicast Reverse Path Forwarding)
uRPF ingress filtering drops packets arriving on an interface if the source IP address is not reachable via that same interface, blocking IP spoofing.
Which type of attack is specifically designed to exhaust firewall connection table resources?
Answer: SYN flood
A SYN flood sends a high volume of TCP SYN packets without completing the handshake, filling the firewall's connection state table and denying service to legitimate users.
What is the security advantage of deploying firewalls in an active-passive high availability (HA) pair?
Answer: It ensures continuous protection if the primary firewall fails
An active-passive HA pair keeps a standby firewall synchronized and ready to take over immediately if the primary fails, maintaining continuous perimeter protection.
A security architect recommends placing database servers in a separate network zone isolated from the DMZ. What security principle does this BEST support?
Answer: Defense in depth through network segmentation
Isolating database servers into their own zone enforces defense in depth — an attacker who compromises the DMZ still faces additional barriers before reaching sensitive data.
Which protocol is commonly used by modern firewalls and routers to share threat intelligence and dynamically update access control lists?
Answer: BGP Flowspec
BGP Flowspec allows routers and firewalls to receive and propagate traffic filtering rules dynamically, enabling rapid response to distributed threats like DDoS.