Network Perimeter Defense Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Perimeter Defense flashcards as text
Which firewall rule processing model evaluates rules from top to bottom and stops at the first match?
Answer: First-match processing
Most firewalls use first-match (top-down) processing, so rule order is critical — more specific rules must appear before broader ones.
A penetration tester discovers that the company's firewall allows all outbound traffic on port 443. Which attack vector does this MOST enable?
Answer: Command-and-control communications using HTTPS tunneling
Unrestricted outbound HTTPS allows malware to use port 443 for encrypted C2 communication, blending with legitimate web traffic.
What is the role of a reverse proxy in perimeter defense?
Answer: It sits in front of internal servers and forwards external client requests to them
A reverse proxy accepts inbound connections on behalf of backend servers, hiding internal server details and enabling inspection or load balancing.
An organization uses geolocation-based IP blocking at the perimeter. What is a significant limitation of this control?
Answer: Attackers can bypass it using VPNs or proxy servers in allowed regions
Geolocation blocking can be easily circumvented by routing traffic through a VPN exit node or proxy located in a permitted country.
Which of the following BEST describes the function of a honeypot in perimeter defense?
Answer: It acts as a decoy system to detect and study attacker behavior
A honeypot is a decoy resource that attracts attackers, enabling defenders to detect intrusions and analyze attack techniques without risk to real assets.
During a firewall audit, you find a rule that allows ANY source to reach ANY destination on ANY port. What should be done FIRST?
Answer: Identify the business justification for the rule before modifying it
Before modifying or removing any firewall rule, you must determine whether it supports a legitimate business function to avoid unintended service disruptions.
Which perimeter defense technology creates an encrypted tunnel between a remote user and the corporate network, extending the trusted perimeter?
Answer: Virtual Private Network (VPN)
A VPN establishes an encrypted tunnel that allows remote users to securely access internal resources as if they were on the corporate network.