CAS-002 · Question #60
A corporation relies on a server running a trusted operating system to broker data transactions between different security zones on their network. Each zone is a separate domain and the only…
The correct answer is C. A NIPS on the switch in Zone C, an antivirus server in Zone A, and a patch server in Zone B. Zone analysis determines the correct placement: Zone A is internet-adjacent and exposed to external threats - it needs an antivirus server to scan inbound content and protect hosts from malware. Zone B is a closed R&D network - isolated but still requiring a patch server to…
Question
A corporation relies on a server running a trusted operating system to broker data transactions between different security zones on their network. Each zone is a separate domain and the only connection between the networks is via the trusted server. The three zones at the corporation are as followeD. Zone A connects to a network, which is also connected to the Internet through a router. Zone B to a closed research and development network. Zone C to an intermediary switch supporting a SAN, dedicated to long-term audit log and file storage, so the corporation meets compliance requirements. A firewall is deployed on the inside edge of the Internet connected router. Which of the following is the BEST location to place other security equipment?
Options
- AHIPS on all hosts in Zone A and B, and an antivirus and patch server in Zone C.
- BA WAF on the switch in Zone C, an additional firewall in Zone A, and an antivirus server in
- CA NIPS on the switch in Zone C, an antivirus server in Zone A, and a patch server in Zone B.
- DA NIDS on the switch in Zone C, a WAF in Zone A, and a firewall in Zone B.
How the community answered
(21 responses)- A14% (3)
- B5% (1)
- C57% (12)
- D24% (5)
Explanation
Zone analysis determines the correct placement: Zone A is internet-adjacent and exposed to external threats - it needs an antivirus server to scan inbound content and protect hosts from malware. Zone B is a closed R&D network - isolated but still requiring a patch server to keep systems updated without internet access, reducing vulnerability exploitation risk. Zone C hosts the SAN storing compliance audit logs - placing a NIPS on the switch here detects and alerts on anomalous or unauthorized access to audit storage, which is critical for maintaining log integrity and compliance. A WAF in Zone C (B) is misplaced since Zone C has no web application traffic. A NIDS in Zone C is passive (no prevention), and a WAF in Zone A (D) is beneficial but less complete than answer C's coverage.
Topics
Community Discussion
No community discussion yet for this question.