CAS-003 · Question #274
Which of the following BEST describes the implications of placing an IDS device inside or outside of the corporate firewall?
The correct answer is B. Placing the IDS device outside the firewall will allow it to monitor potential remote attacks. Placing the IDS outside the firewall gives it visibility into all inbound attack traffic before the firewall filters it. This allows it to detect and alert on external/remote attack attempts - port scans, exploit attempts, reconnaissance - even those the firewall ultimately…
Question
Which of the following BEST describes the implications of placing an IDS device inside or outside of the corporate firewall?
Options
- APlacing the IDS device inside the firewall will allow it to monitor potential internal attacks but
- BPlacing the IDS device outside the firewall will allow it to monitor potential remote attacks
- CPlacing the IDS device inside the firewall will allow it to monitor potential remote attacks but
- DPlacing the IDS device outside the firewall will allow it to monitor potential remote attacks but
How the community answered
(28 responses)- A4% (1)
- B75% (21)
- C14% (4)
- D7% (2)
Explanation
Placing the IDS outside the firewall gives it visibility into all inbound attack traffic before the firewall filters it. This allows it to detect and alert on external/remote attack attempts - port scans, exploit attempts, reconnaissance - even those the firewall ultimately blocks. The trade-off is a much higher volume of alerts (noise), since the IDS sees all traffic the internet throws at the perimeter. Placing the IDS inside the firewall reduces noise (it only sees traffic the firewall permits) but misses the broader picture of attack attempts. Option B correctly captures the primary benefit of external placement: monitoring potential remote attacks against the perimeter.
Topics
Community Discussion
No community discussion yet for this question.