nerdexam
CompTIA

CAS-002 · Question #52

A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC highlighted the…

The correct answer is A. In front of the Internet firewall and in front of the DMZs. Two requirements drive this placement: (1) Fingerprinting unfiltered inbound traffic requires the NIPS to be placed before any firewall - i.e., in front of the Internet firewall - so it sees raw, unmanipulated traffic before any filtering occurs. (2) Monitoring all inbound and…

Technical Integration of Enterprise Components

Question

A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC highlighted the following requirements:

Perform fingerprinting on unfiltered inbound traffic to the company Monitor all inbound and outbound traffic to the DMZ's In which of the following places should the NIPS be placed in the network?

Options

  • AIn front of the Internet firewall and in front of the DMZs
  • BIn front of the Internet firewall and in front of the internal firewall
  • CIn front of the Internet firewall and behind the internal firewall
  • DBehind the Internet firewall and in front of the DMZs

How the community answered

(18 responses)
  • A
    78% (14)
  • B
    6% (1)
  • C
    6% (1)
  • D
    11% (2)

Explanation

Two requirements drive this placement: (1) Fingerprinting unfiltered inbound traffic requires the NIPS to be placed before any firewall - i.e., in front of the Internet firewall - so it sees raw, unmanipulated traffic before any filtering occurs. (2) Monitoring all inbound and outbound traffic to DMZs requires a NIPS sensor in front of the DMZs. Answer A ('in front of the Internet firewall and in front of the DMZs') satisfies both requirements simultaneously. Placing the NIPS behind the Internet firewall (D) would mean it only sees already-filtered traffic, failing requirement 1. Options B and C place sensors behind the Internet firewall or at the internal firewall, neither of which captures unfiltered inbound traffic.

Topics

#NIPS placement#DMZ architecture#firewall topology#network security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice