312-50 exam dumps

312-50 practice question 258 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 258

Single answer▪ IDS, IPS, Firewall, and Honeypot Concepts

A company has deployed a public web application in a DMZ after several incidents involving SQL injection attempts and automated vulnerability scanning. The security team wants to achieve three goals: (1) block clearly malicious web requests before they reach the server, (2) detect and log suspicious activity for later analysis, and (3) divert opportunistic attackers away from production systems to gather threat intelligence. Which combination of technologies best meets these goals?

  1. A

    Deploy a network-based IPS inline in front of the web server, enable an IDS to monitor and alert on suspicious traffic, and place a honeypot in a controlled segment that is isolated from production

  2. B

    Deploy a stateless packet-filtering firewall only, because it can both block SQL injection payloads and safely collect attacker behavior in detail

  3. C

    Deploy a host-based IDS on the web server only, because it can prevent malicious packets from reaching the application and redirect attackers to decoy services

  4. D

    Deploy a honeypot in the same production VLAN as the web server, because attackers are more likely to interact with it and it can transparently block malicious traffic

Show answer and explanation

Correct answer: A

Explanation

The best answer is the combination of IPS, IDS, and a properly isolated honeypot because the scenario requires prevention, detection, and deception. In general security architecture, an intrusion prevention system (IPS) is deployed inline so it can actively block or reject malicious traffic, while an intrusion detection system (IDS) monitors and alerts without necessarily interrupting traffic flow. Firewalls primarily enforce access-control policy based on network rules and, unless they include advanced application-layer inspection capabilities, are not sufficient by themselves to stop attacks such as SQL injection. Honeypots are intentionally exposed decoy systems used to observe attacker behavior and collect threat intelligence, but they should be segmented and closely monitored to avoid introducing risk into production. These roles align with common best practices from vendor guidance and frameworks such as NIST defensive architecture principles: use preventive controls to stop known bad activity, detective controls to provide visibility and evidence, and deception technologies in carefully isolated environments to improve intelligence collection.

  • A. Correct.

    Correct. An inline IPS is designed to actively block or drop malicious traffic before it reaches the target, which aligns with the requirement to stop clearly malicious web requests. An IDS provides visibility, logging, and alerting for suspicious activity, supporting detection and forensic analysis. A honeypot, when properly isolated from production, can attract scans and low-sophistication attackers and help collect indicators of compromise, attacker techniques, and behavioral data without increasing risk to the live environment.

  • B. Incorrect.

    Incorrect. A basic stateless packet-filtering firewall can enforce IP/port/protocol rules, but it does not reliably inspect application-layer content such as SQL injection payloads in the same way a purpose-built IPS or web application firewall can. It also is not designed to act as a deception system for collecting attacker interaction data. This option reflects the common misconception that any firewall can provide deep application-layer attack detection and honeypot functionality.

  • C. Incorrect.

    Incorrect. A host-based IDS can detect suspicious activity on the server, such as file changes, log anomalies, or local events, but IDS technology is generally passive and does not inherently stop malicious packets before they reach the application. It also does not redirect attackers to decoy services. This option confuses detection with prevention and overstates the role of a host-based IDS.

  • D. Incorrect.

    Incorrect. A honeypot should not be placed in the same production VLAN without strict controls, because it can increase risk if compromised and used as a pivot point. A honeypot also does not transparently block malicious traffic headed to production assets; it is a deception and intelligence-gathering system, not a prevention control. This option reflects poor segmentation practice and misunderstanding of honeypot purpose.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam