312-50 exam dumps

312-50 practice question 279 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 279

Single answer▪ IDS/Firewall Evasion Countermeasures

During an authorized internal security assessment, you discover that the perimeter IDS is missing several test attacks that use tiny fragmented IP packets and overlapping TCP segments. The firewall still allows the traffic because it only applies basic ACL rules and does not fully normalize packets before forwarding them. The security manager asks which control would most directly reduce this IDS/firewall evasion technique without relying on signatures alone. What should you recommend?

  1. A

    Deploy traffic normalization and full packet reassembly at the firewall/IPS before inspection

  2. B

    Lower the IDS alert threshold so it generates more alarms on suspicious traffic volumes

  3. C

    Disable TCP checksum validation so fragmented packets can be inspected faster

  4. D

    Block all ICMP traffic at the perimeter to prevent packet fragmentation attacks

Show answer and explanation

Correct answer: A

Explanation

This scenario targets a classic IDS/firewall evasion issue: the security device and the endpoint interpret fragmented or overlapping traffic differently. The most effective countermeasure is protocol normalization with fragment reassembly and TCP stream reassembly before policy enforcement or detection. This concept is consistent with best practices in modern firewalls, IPS platforms, and IDS engines such as Snort and Suricata, which support defragmentation and stream preprocessing/reassembly specifically to counter evasion attempts. RFC 1858 discusses security considerations for IP fragmentation, and operational guidance from major vendors emphasizes normalizing traffic so inspection engines see canonical packet streams. Simply increasing alerts, disabling validation, or blocking ICMP does not solve the parsing inconsistency that makes this evasion possible.

  • A. Correct.

    Correct. Traffic normalization and packet reassembly are primary countermeasures against fragmentation and overlapping-segment evasion. By reassembling fragments and handling ambiguities consistently before IDS/IPS inspection, the security stack sees the same packet stream the endpoint would process. This removes a common evasion gap where the IDS inspects fragments differently from the destination host.

  • B. Incorrect.

    Incorrect. Lowering alert thresholds may increase sensitivity to some noisy attacks, but it does not address the root problem of protocol ambiguity caused by fragmentation or overlapping TCP segments. The IDS can still misinterpret or miss the payload if packets are not normalized or reassembled first.

  • C. Incorrect.

    Incorrect. Disabling checksum validation would weaken security and packet integrity checks rather than improve inspection. Attackers can exploit malformed traffic, and proper validation is part of defending against evasive packets. Performance optimization should not come at the cost of accepting invalid traffic.

  • D. Incorrect.

    Incorrect. Blocking ICMP does not directly stop IP fragmentation or TCP segment overlap evasion. Fragmentation is an IP-layer behavior and can occur without ICMP. Also, blanket ICMP blocking is generally not a best practice because it can break legitimate network functions such as Path MTU Discovery and troubleshooting.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam