nerdexam
CompTIA

CAS-001 · Question #93

A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC highlighted the…

The correct answer is A. In front of the Internet firewall and in front of the DMZs. The two SOC requirements dictate two distinct NIPS placements. First, 'fingerprinting on unfiltered inbound traffic' requires a NIPS sensor placed in front of (outside) the Internet-facing firewall, where traffic has not yet been filtered or altered by firewall rules. Second…

Enterprise Security

Question

A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC highlighted the following requirements:

  • Perform fingerprinting on unfiltered inbound traffic to the company
  • Monitor all inbound and outbound traffic to the DMZ's

In which of the following places should the NIPS be placed in the network?

Options

  • AIn front of the Internet firewall and in front of the DMZs
  • BIn front of the Internet firewall and in front of the internal firewall
  • CIn front of the Internet firewall and behind the internal firewall
  • DBehind the Internet firewall and in front of the DMZs

How the community answered

(35 responses)
  • A
    66% (23)
  • B
    6% (2)
  • C
    20% (7)
  • D
    9% (3)

Explanation

The two SOC requirements dictate two distinct NIPS placements. First, 'fingerprinting on unfiltered inbound traffic' requires a NIPS sensor placed in front of (outside) the Internet-facing firewall, where traffic has not yet been filtered or altered by firewall rules. Second, 'monitoring all inbound and outbound traffic to the DMZs' requires a NIPS placed in front of (at the edge of) each DMZ segment. Option A satisfies both: one sensor outside the firewall for raw fingerprinting and one in front of the DMZs for full DMZ traffic visibility. Options B and C misplace the second sensor relative to the internal network rather than the DMZs. Option D places both sensors after the firewall, missing unfiltered traffic.

Topics

#NIPS placement#network architecture#DMZ#internet-facing security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice