โ† All CCP Flashcard Decks

Firewall & IDS/IPS Tuning Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Firewall & IDS/IPS Tuning flashcards as text
  1. Which IDS/IPS evasion technique involves splitting malicious payload across multiple TCP segments to avoid signature matching?

    Answer: Fragmentation and session splicing

    Session splicing breaks a payload across multiple small TCP segments, exploiting IDS systems that do not reassemble streams before pattern matching.

  2. An organization deploys a Web Application Firewall (WAF) in front of its API gateway. What type of attack is the WAF LEAST suited to prevent without additional tuning?

    Answer: Business logic abuse specific to the application

    WAFs excel at pattern-based attack detection but cannot understand application-specific business logic, making logic abuse attacks like excessive API calls hard to detect without custom rules.

  3. What is the purpose of a 'tarpit' or honeypot integrated with an IPS response?

    Answer: To slow down or trap attackers while gathering intelligence on their methods

    A tarpit or honeypot deliberately engages attackers to waste their time and collect intelligence without exposing real assets.

  4. A NGFW is configured with application-layer inspection. Which OSI layer does it inspect beyond traditional packet filtering?

    Answer: Layer 7 (Application)

    Next-generation firewalls add Layer 7 application-layer inspection, enabling them to identify and control specific applications regardless of port.

  5. When tuning IDS rules for a PCI DSS environment, which traffic type should ALWAYS generate an alert regardless of baseline suppression settings?

    Answer: Cleartext transmission of cardholder data outside the CDE

    PCI DSS requires detection of cleartext cardholder data transmission outside the cardholder data environment as a mandatory compliance control.

  6. An administrator notices that an IPS signature for a CVE is triggering on encrypted HTTPS traffic without SSL inspection enabled. What is the MOST likely cause?

    Answer: The signature is matching on TCP header anomalies rather than payload

    Without SSL/TLS inspection, an IPS cannot read encrypted payloads, so any match must be based on observable network-layer characteristics like TCP behavior or certificate metadata.

  7. Which firewall architecture places a screened subnet between two firewalls to host public-facing services?

    Answer: DMZ (Demilitarized Zone) architecture

    A DMZ architecture uses two firewalls to create an isolated segment where public services are hosted, limiting exposure of the internal network even if a DMZ host is compromised.