nerdexam
Cisco

350-201 · Question #6

An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addresses and internal…

The correct answer is B. Move the IPS to before the firewall facing the outside network. When an IPS generates false positives from trusted internal IP addresses, relocating it to the network perimeter before the firewall ensures it only inspects untrusted external traffic, eliminating the internal noise.

Network Intrusion Analysis

Question

An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addresses and internal devices. The final incident report stated that these alerts were false positives and that no intrusions were detected. What action should be taken to harden the network?

Options

  • AMove the IPS to after the firewall facing the internal network
  • BMove the IPS to before the firewall facing the outside network
  • CConfigure the proxy service on the IPS
  • DConfigure reverse port forwarding on the IPS

How the community answered

(54 responses)
  • A
    4% (2)
  • B
    81% (44)
  • C
    6% (3)
  • D
    9% (5)

Why each option

When an IPS generates false positives from trusted internal IP addresses, relocating it to the network perimeter before the firewall ensures it only inspects untrusted external traffic, eliminating the internal noise.

AMove the IPS to after the firewall facing the internal network

Moving the IPS to after the firewall facing the internal network would expose it to even more internal trusted device traffic, compounding the false positive problem rather than resolving it.

BMove the IPS to before the firewall facing the outside networkCorrect

Placing the IPS before the firewall on the external-facing side means it inspects inbound internet traffic prior to any filtering, focusing exclusively on untrusted external sources. This removes internal trusted IP addresses from the IPS inspection path entirely, which was the root cause of the false positive alerts, and allows the firewall to handle internal traffic policy enforcement.

CConfigure the proxy service on the IPS

Configuring a proxy service on the IPS is unrelated to placement or traffic segmentation and does not address false positives generated from trusted internal IP addresses.

DConfigure reverse port forwarding on the IPS

Reverse port forwarding is a network redirection technique with no relevance to IPS sensor placement or alert tuning.

Concept tested: IPS placement to reduce false positives from internal traffic

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/fdm/fptd-fdm-config-guide-630/fptd-fdm-intrusion.html

Topics

#IPS placement#false positives#network hardening#intrusion detection

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice