312-50 exam dumps

312-50 practice question 259 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 259

Select 2▪ IDS, IPS, Firewall, and Honeypot Concepts

A security team is investigating repeated SSH brute-force attempts coming from the Internet against a Linux administration server in the DMZ. Management wants a control that can automatically stop the attack in real time before it reaches the server, while minimizing exposure of the production host. The team also wants to study attacker behavior without risking the actual server. Which TWO actions best meet these goals?

  1. A

    Deploy a network-based IPS inline in front of the DMZ server and configure it to block SSH brute-force patterns

  2. B

    Deploy a network-based IDS on a SPAN/TAP port to detect the activity and rely on analysts to manually block the source addresses later

  3. C

    Place a honeypot that mimics an SSH service in a controlled segment to attract and observe the attackers

  4. D

    Replace the perimeter firewall with a stateless packet filter and allow TCP port 22 only from any source

  5. E

    Disable firewall logging to reduce alert volume during the attack

Show answer and explanation

Correct answers: A, C

Explanation

The best answer is to combine prevention and deception: use an inline IPS to block malicious SSH activity in real time, and use a honeypot to safely collect intelligence on attacker behavior. This reflects the distinct roles of these technologies. IDS detects and alerts but does not normally prevent because it is not inline. IPS is positioned inline specifically to inspect and block traffic based on signatures, anomalies, or policy. Firewalls enforce access-control policy, but simply permitting SSH from any source does not mitigate brute-force behavior and may increase risk. Honeypots are decoy systems or services intended to detect, divert, and study unauthorized activity with limited impact on production assets. These distinctions are consistent with common vendor and standards guidance, including NIST SP 800-94 on intrusion detection and prevention systems, which differentiates passive IDS from active IPS, and general defensive best practices for layered security and controlled deception environments.

  • A. Correct.

    Correct. An IPS is designed to sit inline and take active measures such as dropping packets or resetting connections when malicious traffic is detected. For SSH brute-force attacks, an inline network-based IPS can enforce signatures, rate-based rules, or behavioral policies to stop the attack before it reaches the DMZ server. This directly addresses the requirement for real-time prevention.

  • B. Incorrect.

    Incorrect. An IDS is primarily a passive detection technology. When deployed via SPAN or TAP, it can alert on SSH brute-force attempts, but it does not inherently block traffic because it is out of band. Manual blocking may help eventually, but it does not meet the stated requirement to stop the attack in real time before it reaches the server.

  • C. Correct.

    Correct. A honeypot is appropriate when the team wants to observe attacker tools, commands, and behavior without exposing the production system. By presenting a decoy SSH service in a controlled environment, defenders can gather intelligence while reducing risk to the real administration server. This satisfies the requirement to study attacker behavior safely.

  • D. Incorrect.

    Incorrect. A stateless packet filter is a downgrade in capability for most perimeter use cases and simply allowing TCP 22 from any source increases exposure rather than reducing it. It does not provide attack behavior analysis and is not a targeted control for stopping brute-force attempts beyond basic port allowance or denial.

  • E. Incorrect.

    Incorrect. Disabling firewall logging reduces visibility during an active attack and makes investigation harder. Logging is important for correlation with IDS/IPS and honeypot events. Reducing alert fatigue should be handled through tuning, rate limiting, aggregation, or SIEM correlation, not by turning off useful logs.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam