CAS-002 · Question #87
A company data center provides Internet based access to email and web services. The firewall is separated into four zones: RED ZONE is an Internet zone ORANGE ZONE a Web DMZ YELLOW ZONE an email DMZ…
The correct answer is D. RED ZONE: NIPS. Placing a single NIPS appliance in the Internet-facing RED ZONE provides the broadest perimeter threat prevention across all downstream DMZ zones within a limited budget.
Question
A company data center provides Internet based access to email and web services. The firewall is separated into four zones:
RED ZONE is an Internet zone ORANGE ZONE a Web DMZ YELLOW ZONE an email DMZ GREEN ZONE is a management interface There are 15 email servers and 10 web servers. The data center administrator plugs a laptop into the management interface to make firewall changes. The administrator would like to secure this environment but has a limited budget. Assuming each addition is an appliance, which of the following would provide the MOST appropriate placement of security solutions while minimizing the expenses?
Options
- ARED ZONE: none
- BRED ZONE: Virus Scanner, SPAM Filter
- CRED ZONE: WAF, Virus Scanner
- DRED ZONE: NIPS
How the community answered
(34 responses)- A9% (3)
- B6% (2)
- C21% (7)
- D65% (22)
Why each option
Placing a single NIPS appliance in the Internet-facing RED ZONE provides the broadest perimeter threat prevention across all downstream DMZ zones within a limited budget.
Placing no appliance in the RED ZONE leaves the Internet boundary completely undefended, offering no perimeter protection for the downstream DMZ segments.
A Virus Scanner and SPAM Filter in the RED ZONE are relevant only to email traffic and provide no protection against web-based attacks targeting the 10 web servers in the ORANGE ZONE.
A WAF combined with a Virus Scanner increases cost and covers only web traffic, providing no defense for email threats and less comprehensive coverage than a NIPS.
A NIPS positioned at the RED ZONE Internet boundary inspects and actively blocks malicious traffic before it can reach either the Web DMZ or the Email DMZ, providing unified protection for both sets of servers with one appliance. Because the budget is constrained to a single appliance per zone, the RED ZONE NIPS delivers the highest coverage per dollar by defending all downstream zones simultaneously from a single inspection point.
Concept tested: NIPS placement for cost-effective multi-zone perimeter defense
Source: https://csrc.nist.gov/publications/detail/sp/800-94/final
Topics
Community Discussion
No community discussion yet for this question.