nerdexam
GAQM

CPEH-001 · Question #227

A penetration test was done at a company. After the test, a report was written and given to the company's IT authorities. A section from the report is shown below: Access List should be written…

The correct answer is A. A stateful firewall can be used between intranet (LAN) and DMZ. See the full explanation below for the reasoning.

Question

A penetration test was done at a company. After the test, a report was written and given to the company's IT authorities. A section from the report is shown below:

Access List should be written between VLANs. Port security should be enabled for the intranet. A security solution which filters data packets should be set between intranet (LAN) and DMZ. A WAF should be used in front of the web applications. According to the section from the report, which of the following choice is true?

Options

  • AA stateful firewall can be used between intranet (LAN) and DMZ.
  • BThere is access control policy between VLANs.
  • CMAC Spoof attacks cannot be performed.
  • DPossibility of SQL Injection attack is eliminated.

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    18% (7)
  • C
    8% (3)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice