CISM · Question #11
Several months after the installation of a new firewall with intrusion prevention features to block malicious activity, a breach was discovered that came in through the firewall shortly after…
The correct answer is D. log monitoring. Early detection of a breach that successfully bypassed a firewall relies on continuous analysis of firewall activity logs.
Question
Several months after the installation of a new firewall with intrusion prevention features to block malicious activity, a breach was discovered that came in through the firewall shortly after installation. This breach could have been detected earlier by implementing firewall:
Options
- Aweb surfing controls
- Bpacket filtering
- Capplication awareness
- Dlog monitoring
How the community answered
(21 responses)- B5% (1)
- C5% (1)
- D90% (19)
Why each option
Early detection of a breach that successfully bypassed a firewall relies on continuous analysis of firewall activity logs.
Web surfing controls prevent users from accessing certain websites but do not detect breaches coming *in* through the firewall after a successful intrusion.
Packet filtering is a basic firewall function to block traffic based on rules, but it does not *detect* a breach that has already successfully passed through.
Application awareness allows the firewall to understand and control application-specific traffic, which is a prevention feature, not an early detection mechanism for a successful breach.
Firewall logs contain records of all traffic, including denied and allowed connections; regular log monitoring helps identify anomalous patterns or successful penetrations that indicate a breach, even if initial prevention failed. This enables proactive response before significant damage occurs.
Concept tested: Firewall log analysis for breach detection
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-92.pdf
Topics
Community Discussion
No community discussion yet for this question.