ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 188 - SY0-701 discussion

Report
Export

A company tested and validated the effectiveness of network security appliances within the corporate network. The IDS detected a high rate of SQL injection attacks against the company's servers, and the company's perimeter firewall is at capacity. Which of the following would be the best action to maintain security and reduce the traffic to the perimeter firewall?

A.
Set the appliance to IPS mode and place it in front of the company firewall.
Answers
A.
Set the appliance to IPS mode and place it in front of the company firewall.
B.
Convert the firewall to a WAF and use IPSec tunnels to increase throughput.
Answers
B.
Convert the firewall to a WAF and use IPSec tunnels to increase throughput.
C.
Set the firewall to fail open if it is overloaded with traffic and send alerts to the SIEM.
Answers
C.
Set the firewall to fail open if it is overloaded with traffic and send alerts to the SIEM.
D.
Configure the firewall to perform deep packet inspection and monitor TLS traffic.
Answers
D.
Configure the firewall to perform deep packet inspection and monitor TLS traffic.
Suggested answer: A

Explanation:

Given the scenario where an Intrusion Detection System (IDS) has detected a high rate of SQL injection attacks and the perimeter firewall is at capacity, the best action would be to set the appliance to Intrusion Prevention System (IPS) mode and place it in front of the company firewall. This approach has several benefits:

Intrusion Prevention System (IPS): Unlike IDS, which only detects and alerts on malicious activity, IPS can actively block and prevent those activities. Placing an IPS in front of the firewall means it can filter out malicious traffic before it reaches the firewall, reducing the load on the firewall and enhancing overall security.

Reducing Traffic Load: By blocking SQL injection attacks and other malicious traffic before it reaches the firewall, the IPS helps maintain the firewall's performance and prevents it from becoming a bottleneck.

Enhanced Security: The IPS provides an additional layer of defense, identifying and mitigating threats in real-time.

Option B (Convert the firewall to a WAF and use IPSec tunnels) would not address the primary issue of reducing traffic to the firewall effectively. Option C (Set the firewall to fail open) would compromise security. Option D (Deep packet inspection) could be resource-intensive and might not alleviate the firewall capacity issue effectively.

asked 02/10/2024
Jahcorey Howze
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first