nerdexam
EC-Council

312-49 · Question #379

You are running through a series of tests on your network to check for any security vulnerabilities. After normal working hours, you initiate a DoS attack against your external firewall. The…

The correct answer is A. The firewall failed-open. A firewall 'failed-open' means that when the firewall crashed or became overwhelmed, it defaulted to allowing all traffic through rather than blocking it. This is the most dangerous failure mode for a security device. 'Fail-closed' (the preferred behavior) would have dropped…

Submitted by fernanda_arg· Apr 18, 2026Network Forensics

Question

You are running through a series of tests on your network to check for any security vulnerabilities. After normal working hours, you initiate a DoS attack against your external firewall. The firewall Quickly freezes up and becomes unusable. You then initiate an FTP connection from an external IP into your internal network. The connection is successful even though you have FTP blocked at the external firewall. What has happened?

Options

  • AThe firewall failed-open
  • BThe firewall failed-closed
  • CThe firewall ACL has been purged
  • DThe firewall failed-bypass

How the community answered

(20 responses)
  • A
    75% (15)
  • B
    5% (1)
  • C
    5% (1)
  • D
    15% (3)

Explanation

A firewall 'failed-open' means that when the firewall crashed or became overwhelmed, it defaulted to allowing all traffic through rather than blocking it. This is the most dangerous failure mode for a security device. 'Fail-closed' (the preferred behavior) would have dropped all traffic upon failure. Because the DoS attack caused the firewall to freeze and then fail-open, the FTP connection - which should have been blocked - was permitted. This scenario highlights why firewalls should be configured to fail-closed by default.

Topics

#Firewall Security#Denial of Service (DoS)#Network Vulnerabilities#Fail-open

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice