โ† All CCP Flashcard Decks

Network Perimeter Defense Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Perimeter Defense flashcards as text
  1. A security engineer wants to prevent external attackers from mapping internal IP addresses using ICMP. Which firewall rule best addresses this?

    Answer: Block all inbound ICMP echo requests at the perimeter

    Blocking inbound ICMP echo requests prevents external parties from using ping sweeps to discover live internal hosts.

  2. Which DMZ architecture places web servers between two separate firewalls with different vendors?

    Answer: Dual-firewall DMZ

    A dual-firewall DMZ uses two firewalls (often from different vendors) to isolate the DMZ, reducing the risk of a single firewall compromise exposing internal networks.

  3. An IPS is generating thousands of false positives, overwhelming the SOC team. What is the BEST immediate tuning action?

    Answer: Create exception rules for known-good traffic sources generating false alerts

    Creating exception rules for verified legitimate traffic sources reduces false positives while keeping detection active for genuine threats.

  4. What is the primary purpose of a network access control (NAC) solution at the perimeter?

    Answer: Enforce endpoint health checks before granting network access

    NAC enforces posture assessment (patch level, AV status, etc.) on endpoints before allowing them onto the network.

  5. A company deploys a next-generation firewall (NGFW). Which capability distinguishes it from a traditional stateful firewall?

    Answer: It performs deep packet inspection including application-layer identification

    NGFWs perform deep packet inspection and can identify applications regardless of port, going beyond the port/protocol focus of stateful firewalls.

  6. Which technique do attackers use to bypass perimeter firewalls by tunneling malicious traffic inside allowed protocols like DNS or HTTP?

    Answer: Protocol tunneling

    Protocol tunneling encapsulates unauthorized traffic within permitted protocols (e.g., DNS tunneling) to evade firewall controls.

  7. An organization requires that all outbound web traffic be inspected for data exfiltration. Which perimeter control BEST fulfills this requirement?

    Answer: Egress filtering with a secure web gateway (SWG)

    A secure web gateway with egress filtering inspects and controls outbound HTTP/HTTPS traffic, enabling DLP and content inspection.