ExamGecko
Question list
Search
Search

Question 339 - CISM discussion

Report
Export

Which of the following is the BEST method for determining whether a firewall has been configured to provide a comprehensive perimeter defense9

A.
A validation of the current firewall rule set
Answers
A.
A validation of the current firewall rule set
B.
A port scan of the firewall from an internal source
Answers
B.
A port scan of the firewall from an internal source
C.
A ping test from an external source
Answers
C.
A ping test from an external source
D.
A simulated denial of service (DoS) attack against the firewall
Answers
D.
A simulated denial of service (DoS) attack against the firewall
Suggested answer: A

Explanation:

A validation of the current firewall rule set is the best method for determining whether a firewall has been configured to provide a comprehensive perimeter defense because it verifies that the firewall rules are consistent, accurate, and effective in allowing or blocking traffic according to the security policies and standards of the organization. A port scan of the firewall from an internal source is not a good method because it does not test the firewall's behavior from an external perspective, which is more relevant for perimeter defense. A ping test from an external source is not a good method because it only tests the firewall's availability and responsiveness, not its security or functionality. A simulated denial of service (DoS) attack against the firewall is not a good method because it only tests the firewall's resilience and performance under high traffic load, not its security or functionality.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing

asked 01/10/2024
Gabriel Pereira Dias
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first