Network Perimeter Defense Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Perimeter Defense flashcards as text
An organization is evaluating whether to use a cloud-based firewall-as-a-service (FWaaS) instead of on-premises firewalls. What is the PRIMARY security consideration for distributed branch offices?
Answer: FWaaS applies consistent policy enforcement regardless of user location without backhauling traffic
FWaaS enables uniform policy enforcement at the cloud edge, eliminating the need to backhaul branch traffic to a central data center for inspection.
Which perimeter defense strategy involves deceiving attackers with fake vulnerabilities and services to delay and study their actions?
Answer: Deception technology (honeynets)
Deception technology deploys honeynets — networks of honeypots — to lure attackers, gather intelligence, and buy time for defenders to respond.
A company's NGFW supports TLS 1.3 inspection but employees report certificate errors. What is the MOST likely cause?
Answer: The firewall's CA certificate is not trusted by client browsers
SSL inspection requires clients to trust the firewall's re-signing CA certificate; if it's not distributed to client trust stores, browsers display certificate warnings.
In a Zero Trust perimeter model, which statement BEST describes how access decisions are made?
Answer: Access is continuously verified using identity, device posture, and context regardless of network location
Zero Trust requires continuous verification of identity, device health, and context for every access request, rejecting the assumption that internal network location implies trust.
Which attack specifically targets the perimeter by exploiting misconfigured firewall rules that allow traffic from a low-trust DMZ zone to reach high-trust internal zones?
Answer: DMZ to internal zone lateral movement
Misconfigured rules that permit traffic from the DMZ to internal zones allow an attacker who compromises a DMZ server to pivot directly into the trusted internal network.
What is the purpose of a 'security zone' in firewall policy design?
Answer: To group interfaces with similar trust levels and apply consistent policies between zones
Security zones group network interfaces by trust level (e.g., untrusted, DMZ, trusted), allowing administrators to define clear inter-zone policies rather than per-interface rules.
An IDS alert fires on a signature for a known vulnerability, but the target system is running a patched OS version that is not susceptible. This is an example of which IDS issue?
Answer: False positive
A false positive occurs when an IDS generates an alert for traffic that is not actually a successful or viable attack, such as detecting an exploit signature against a patched target.