nerdexam
CompTIA

CAS-002 · Question #274

Which of the following BEST describes the implications of placing an IDS device inside or outside of the corporate firewall?

The correct answer is B. Placing the IDS device outside the firewall will allow it to monitor potential remote attacks. IDS placement determines traffic visibility - outside the firewall captures all raw inbound external traffic, while inside captures only what the firewall allowed through.

Enterprise Security

Question

Which of the following BEST describes the implications of placing an IDS device inside or outside of the corporate firewall?

Options

  • APlacing the IDS device inside the firewall will allow it to monitor potential internal attacks but
  • BPlacing the IDS device outside the firewall will allow it to monitor potential remote attacks
  • CPlacing the IDS device inside the firewall will allow it to monitor potential remote attacks but
  • DPlacing the IDS device outside the firewall will allow it to monitor potential remote attacks but

How the community answered

(19 responses)
  • B
    95% (18)
  • C
    5% (1)

Why each option

IDS placement determines traffic visibility - outside the firewall captures all raw inbound external traffic, while inside captures only what the firewall allowed through.

APlacing the IDS device inside the firewall will allow it to monitor potential internal attacks but

An IDS inside the firewall monitors traffic that has already been filtered, so it sees internal threats and attacks that bypass the firewall, but it misses the broader external attack surface visible to an outside-placed sensor.

BPlacing the IDS device outside the firewall will allow it to monitor potential remote attacksCorrect

Placing an IDS outside the firewall means it inspects the full volume of inbound internet traffic before any filtering occurs, enabling detection of remote and external attacks and providing complete visibility into attack attempts against the organization. This placement also reveals attacker reconnaissance and probing activity that the firewall would otherwise silently drop. However, it offers no visibility into internal lateral movement or threats that originate inside the network perimeter.

CPlacing the IDS device inside the firewall will allow it to monitor potential remote attacks but

An IDS inside the firewall does not effectively monitor remote attacks because the firewall has already filtered most inbound external traffic before the IDS can inspect it.

DPlacing the IDS device outside the firewall will allow it to monitor potential remote attacks but

This choice mischaracterizes the trade-offs of outside-firewall placement; the specific limitation it attributes to this configuration does not accurately reflect standard IDS deployment behavior.

Concept tested: IDS sensor placement inside vs outside the firewall

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-94.pdf

Topics

#IDS placement#firewall#intrusion detection#network monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice