CAS-001 · Question #58
A company data center provides Internet based access to email and web services. The firewall is separated into four zones: - RED ZONE is an Internet zone - ORANGE ZONE a Web DMZ - YELLOW ZONE an…
The correct answer is D. RED ZONE. NIPS. With a limited budget, the highest-value placement of a security appliance is at the internet-facing perimeter - the RED ZONE. A Network Intrusion Prevention System (NIPS) at the RED ZONE inspects and blocks malicious traffic before it reaches the DMZs, protecting all 15 email…
Question
A company data center provides Internet based access to email and web services. The firewall is separated into four zones:
- RED ZONE is an Internet zone
- ORANGE ZONE a Web DMZ
- YELLOW ZONE an email DMZ
- GREEN ZONE is a management interface
There are 15 email servers and 10 web servers. The data center administrator plugs a laptop into the management interface to make firewall changes. The administrator would like to secure this environment but has a limited budget. Assuming each addition is an appliance, which of the following would provide the MOST appropriate placement of security solutions while minimizing the expenses?
Options
- ARED ZONE. None
- BRED ZONE. Virus Scanner, SPAM Filter
- CRED ZONE. WAF, Virus Scanner
- DRED ZONE. NIPS
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C17% (5)
- D69% (20)
Explanation
With a limited budget, the highest-value placement of a security appliance is at the internet-facing perimeter - the RED ZONE. A Network Intrusion Prevention System (NIPS) at the RED ZONE inspects and blocks malicious traffic before it reaches the DMZs, protecting all 15 email servers and 10 web servers simultaneously with a single device. This maximizes coverage per dollar spent. Options B and C propose solutions like virus scanners and WAFs at the RED ZONE, but a WAF is more appropriately placed closer to the web servers (ORANGE ZONE) and a virus scanner at the perimeter is less effective than NIPS for network-level threat blocking. NIPS provides broad-spectrum attack prevention at the highest-risk ingress point, making it the best single investment for a budget-constrained environment.
Topics
Community Discussion
No community discussion yet for this question.