Firewall & IDS/IPS Tuning Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall & IDS/IPS Tuning flashcards as text
Which IDS/IPS evasion technique involves splitting malicious payload across multiple TCP segments to avoid signature matching?
Answer: Fragmentation and session splicing
Session splicing breaks a payload across multiple small TCP segments, exploiting IDS systems that do not reassemble streams before pattern matching.
An organization deploys a Web Application Firewall (WAF) in front of its API gateway. What type of attack is the WAF LEAST suited to prevent without additional tuning?
Answer: Business logic abuse specific to the application
WAFs excel at pattern-based attack detection but cannot understand application-specific business logic, making logic abuse attacks like excessive API calls hard to detect without custom rules.
What is the purpose of a 'tarpit' or honeypot integrated with an IPS response?
Answer: To slow down or trap attackers while gathering intelligence on their methods
A tarpit or honeypot deliberately engages attackers to waste their time and collect intelligence without exposing real assets.
A NGFW is configured with application-layer inspection. Which OSI layer does it inspect beyond traditional packet filtering?
Answer: Layer 7 (Application)
Next-generation firewalls add Layer 7 application-layer inspection, enabling them to identify and control specific applications regardless of port.
When tuning IDS rules for a PCI DSS environment, which traffic type should ALWAYS generate an alert regardless of baseline suppression settings?
Answer: Cleartext transmission of cardholder data outside the CDE
PCI DSS requires detection of cleartext cardholder data transmission outside the cardholder data environment as a mandatory compliance control.
An administrator notices that an IPS signature for a CVE is triggering on encrypted HTTPS traffic without SSL inspection enabled. What is the MOST likely cause?
Answer: The signature is matching on TCP header anomalies rather than payload
Without SSL/TLS inspection, an IPS cannot read encrypted payloads, so any match must be based on observable network-layer characteristics like TCP behavior or certificate metadata.
Which firewall architecture places a screened subnet between two firewalls to host public-facing services?
Answer: DMZ (Demilitarized Zone) architecture
A DMZ architecture uses two firewalls to create an isolated segment where public services are hosted, limiting exposure of the internal network even if a DMZ host is compromised.