nerdexam
CompTIA

CAS-002 · Question #87

A company data center provides Internet based access to email and web services. The firewall is separated into four zones: RED ZONE is an Internet zone ORANGE ZONE a Web DMZ YELLOW ZONE an email DMZ…

The correct answer is D. RED ZONE: NIPS. Placing a single NIPS appliance in the Internet-facing RED ZONE provides the broadest perimeter threat prevention across all downstream DMZ zones within a limited budget.

Technical Integration of Enterprise Components

Question

A company data center provides Internet based access to email and web services. The firewall is separated into four zones:

RED ZONE is an Internet zone ORANGE ZONE a Web DMZ YELLOW ZONE an email DMZ GREEN ZONE is a management interface There are 15 email servers and 10 web servers. The data center administrator plugs a laptop into the management interface to make firewall changes. The administrator would like to secure this environment but has a limited budget. Assuming each addition is an appliance, which of the following would provide the MOST appropriate placement of security solutions while minimizing the expenses?

Options

  • ARED ZONE: none
  • BRED ZONE: Virus Scanner, SPAM Filter
  • CRED ZONE: WAF, Virus Scanner
  • DRED ZONE: NIPS

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    21% (7)
  • D
    65% (22)

Why each option

Placing a single NIPS appliance in the Internet-facing RED ZONE provides the broadest perimeter threat prevention across all downstream DMZ zones within a limited budget.

ARED ZONE: none

Placing no appliance in the RED ZONE leaves the Internet boundary completely undefended, offering no perimeter protection for the downstream DMZ segments.

BRED ZONE: Virus Scanner, SPAM Filter

A Virus Scanner and SPAM Filter in the RED ZONE are relevant only to email traffic and provide no protection against web-based attacks targeting the 10 web servers in the ORANGE ZONE.

CRED ZONE: WAF, Virus Scanner

A WAF combined with a Virus Scanner increases cost and covers only web traffic, providing no defense for email threats and less comprehensive coverage than a NIPS.

DRED ZONE: NIPSCorrect

A NIPS positioned at the RED ZONE Internet boundary inspects and actively blocks malicious traffic before it can reach either the Web DMZ or the Email DMZ, providing unified protection for both sets of servers with one appliance. Because the budget is constrained to a single appliance per zone, the RED ZONE NIPS delivers the highest coverage per dollar by defending all downstream zones simultaneously from a single inspection point.

Concept tested: NIPS placement for cost-effective multi-zone perimeter defense

Source: https://csrc.nist.gov/publications/detail/sp/800-94/final

Topics

#network security zones#NIPS#DMZ architecture#security appliance placement

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice