nerdexam
CompTIA

CAS-001 · Question #58

A company data center provides Internet based access to email and web services. The firewall is separated into four zones: - RED ZONE is an Internet zone - ORANGE ZONE a Web DMZ - YELLOW ZONE an…

The correct answer is D. RED ZONE. NIPS. With a limited budget, the highest-value placement of a security appliance is at the internet-facing perimeter - the RED ZONE. A Network Intrusion Prevention System (NIPS) at the RED ZONE inspects and blocks malicious traffic before it reaches the DMZs, protecting all 15 email…

Technical Integration of Enterprise Components

Question

A company data center provides Internet based access to email and web services. The firewall is separated into four zones:

  • RED ZONE is an Internet zone
  • ORANGE ZONE a Web DMZ
  • YELLOW ZONE an email DMZ
  • GREEN ZONE is a management interface

There are 15 email servers and 10 web servers. The data center administrator plugs a laptop into the management interface to make firewall changes. The administrator would like to secure this environment but has a limited budget. Assuming each addition is an appliance, which of the following would provide the MOST appropriate placement of security solutions while minimizing the expenses?

Options

  • ARED ZONE. None
  • BRED ZONE. Virus Scanner, SPAM Filter
  • CRED ZONE. WAF, Virus Scanner
  • DRED ZONE. NIPS

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    17% (5)
  • D
    69% (20)

Explanation

With a limited budget, the highest-value placement of a security appliance is at the internet-facing perimeter - the RED ZONE. A Network Intrusion Prevention System (NIPS) at the RED ZONE inspects and blocks malicious traffic before it reaches the DMZs, protecting all 15 email servers and 10 web servers simultaneously with a single device. This maximizes coverage per dollar spent. Options B and C propose solutions like virus scanners and WAFs at the RED ZONE, but a WAF is more appropriately placed closer to the web servers (ORANGE ZONE) and a virus scanner at the perimeter is less effective than NIPS for network-level threat blocking. NIPS provides broad-spectrum attack prevention at the highest-risk ingress point, making it the best single investment for a budget-constrained environment.

Topics

#network security zones#NIPS placement#DMZ architecture#defense in depth

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice