312-50 exam dumps

312-50 practice question 263 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 263

Select 2▪ IDS, IPS, Firewall, and Honeypot Solutions

A company hosts a public web application in a DMZ and has recently observed repeated SQL injection attempts and automated vulnerability scans from multiple Internet hosts. The security team wants to reduce the risk of successful exploitation in real time, continue allowing legitimate HTTPS traffic, and gather intelligence on attacker behavior without exposing production systems. Which combination of controls would BEST meet these requirements?

  1. A

    Deploy a network-based IPS in front of the web servers with signatures and anomaly rules tuned for web attacks, and place a honeypot in an isolated segment to attract and study malicious activity

  2. B

    Replace the perimeter firewall with a network IDS so attack traffic can be logged while legitimate traffic continues to pass without interruption

  3. C

    Configure the existing firewall to allow only outbound HTTPS from the web server subnet so inbound SQL injection attempts cannot reach the application

  4. D

    Deploy a honeypot directly on the production web server so attackers interact with it instead of the real application

  5. E

    Use the perimeter firewall to restrict access to only required ports such as 443/TCP, and keep an IDS on a SPAN/TAP port to provide visibility and alerting on suspicious traffic

Show answer and explanation

Correct answers: A, E

Explanation

The best answer is the combination of Options 1 and 5 because the scenario requires both prevention and intelligence gathering while maintaining legitimate HTTPS access. A firewall should continue to enforce basic network access control by permitting only required services, such as 443/TCP to the public web application, which aligns with standard network hardening guidance from sources such as NIST SP 800-41 on firewalls. To reduce exploitation risk in real time, an IPS is more appropriate than an IDS because it can take active measures such as dropping packets, resetting connections, or blocking malicious patterns. For visibility and investigation, an IDS connected to a SPAN or TAP is a common deployment pattern, consistent with detection-focused guidance such as NIST SP 800-94 on intrusion detection and prevention technologies. Finally, a honeypot is useful for collecting indicators and observing attacker techniques, but it should be isolated from production systems. The key distinction tested here is the operational role of each control: firewall for access control, IPS for active prevention, IDS for monitoring and alerting, and honeypot for deception and threat intelligence.

  • A. Correct.

    Correct. A network-based IPS can actively block or reset malicious sessions in real time, which directly addresses the requirement to reduce exploitation risk while still permitting legitimate traffic. Tuning signatures and behavioral rules for web attacks such as SQL injection improves effectiveness and reduces false positives. An isolated honeypot is also appropriate for gathering attacker TTPs, tools, and indicators without risking the production web application.

  • B. Incorrect.

    Incorrect. An IDS is primarily a detective control and does not normally block traffic; replacing a firewall with an IDS would reduce enforcement capability. Firewalls and IDS serve different purposes: a firewall enforces access control policy, while an IDS monitors and alerts on suspicious activity. Logging alone does not meet the requirement to reduce risk in real time.

  • C. Incorrect.

    Incorrect. Public web servers must accept inbound HTTPS for users to reach the application. Allowing only outbound HTTPS from the web server subnet would break normal business functionality rather than selectively stopping SQL injection. This option reflects a misunderstanding between direction-based firewall policy and application-layer attack prevention.

  • D. Incorrect.

    Incorrect. A honeypot should not be deployed directly on a production server. Honeypots are intended to be decoy systems or services, isolated and monitored so attacker interaction can be observed safely. Putting honeypot functionality on the live web server increases risk and does not safely separate production services from deceptive assets.

  • E. Correct.

    Correct. Restricting exposure to only required ports at the firewall is a core best practice and reduces attack surface. Keeping an IDS on a SPAN or TAP provides passive visibility, alerting, and forensic value without interfering with legitimate traffic. While the IDS does not itself block attacks, in combination with proper firewall policy it supports monitoring and detection, which helps meet the requirement to continue service and improve awareness.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam