312-50 exam dumps

312-50 practice question 280 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 280

Single answer▪ IDS/Firewall Evasion Countermeasures

During an authorized internal security assessment, a tester discovers that an older perimeter firewall and IDS do not consistently detect scans that use packet fragmentation and unusual TCP flag combinations. The security team asks for the most effective countermeasure to reduce the risk of this IDS/firewall evasion technique without disrupting legitimate business traffic. Which action should the team take first?

  1. A

    Enable packet normalization and fragment reassembly on the firewall/IDS, and ensure signatures and inspection policies are updated

  2. B

    Block all ICMP traffic at the perimeter so fragmented packets cannot traverse the network

  3. C

    Disable stateful inspection to reduce CPU load and let the IDS analyze only complete sessions

  4. D

    Rely on NAT at the edge because address translation prevents fragmented and malformed packets from reaching internal hosts

Show answer and explanation

Correct answer: A

Explanation

The best countermeasure to IDS/firewall evasion using fragmentation and unusual TCP flags is to make inspection devices interpret traffic the same way endpoints do. In practice, this means enabling packet normalization, IP fragment reassembly, and robust stateful inspection, while keeping IDS/IPS signatures and firmware current. These measures are aligned with long-standing best practices in network intrusion detection and firewall hardening: normalize ambiguous traffic before policy evaluation, reassemble fragments prior to inspection where supported, and detect suspicious flag combinations such as NULL, FIN, or Xmas scans. Vendor guidance for enterprise firewalls and IDS/IPS platforms commonly recommends fragment handling, anomaly detection, and updated threat signatures specifically to address evasion attempts. ICMP blocking and NAT may play roles in broader network policy, but they do not directly solve fragmentation-based inspection gaps.

  • A. Correct.

    Correct. Packet normalization and IP fragment reassembly are standard countermeasures against IDS/firewall evasion techniques that exploit differences in how endpoints and security devices interpret fragmented, overlapping, or malformed packets. Updating signatures and inspection policies further improves detection of abnormal TCP flag combinations and fragmentation-based scans. This is the most direct and practical first step because it addresses the root cause: inconsistent packet interpretation by inspection devices.

  • B. Incorrect.

    Incorrect. Blocking all ICMP is not an effective primary countermeasure for TCP fragmentation or abnormal TCP flag scan evasion. While some reconnaissance uses ICMP, fragmentation-based IDS evasion is not prevented by simply filtering ICMP. In addition, indiscriminately blocking ICMP can break path MTU discovery and complicate troubleshooting.

  • C. Incorrect.

    Incorrect. Disabling stateful inspection weakens the firewall rather than improving security. Stateful inspection helps track sessions and detect anomalous packets in context. Turning it off would make it easier, not harder, for crafted packets and stealthy scans to bypass controls. This option reflects a misunderstanding that lower processing overhead improves detection quality.

  • D. Incorrect.

    Incorrect. NAT is not a security control designed to stop fragmentation- or flag-based evasion. Address translation may change packet headers, but it does not reliably normalize malicious traffic or reassemble fragments for inspection. Attackers can still send crafted packets through NAT devices if filtering and inspection are not properly configured.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam