312-50 exam dumps

312-50 practice question 281 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 281

Single answer▪ IDS/Firewall Evasion Countermeasures

During an internal security assessment, your team discovers that a stateful firewall and network IDS are deployed between user VLANs and a legacy application server. A tester demonstrates that some probes are getting through by using tiny fragmented TCP packets and unusual flag combinations, making the IDS miss the full payload while the target host still reassembles and processes the traffic. As the security engineer, which countermeasure is the MOST effective to reduce this specific evasion technique while maintaining normal business traffic?

  1. A

    Configure the firewall/IDS to perform full packet normalization and IP fragment reassembly before inspection, and drop suspicious overlapping or tiny fragments

  2. B

    Disable stateful inspection on the firewall so fragmented packets are forwarded faster and can be analyzed by the IDS separately

  3. C

    Allow all fragmented packets but increase the IDS alert threshold to reduce false positives from fragmented traffic

  4. D

    Rely on host-based antivirus on the legacy server, because fragment-based evasion occurs after the traffic passes the network controls

Show answer and explanation

Correct answer: A

Explanation

This question focuses on a classic IDS/firewall evasion issue: the security device and the destination host may interpret fragmented or malformed traffic differently. Effective countermeasures include traffic normalization, IP fragment reassembly, TCP stream reassembly where applicable, and dropping suspicious constructs such as overlapping fragments or invalid flag combinations. These practices are consistent with long-standing IDS/IPS and firewall hardening guidance, including recommendations reflected in major platform documentation and industry best practices such as proper stream/frag preprocessors in network intrusion detection systems, packet normalization in firewalls, and RFC-aware validation of fragmented traffic. The best answer is the one that makes the inspection device see traffic as the endpoint would, reducing ambiguity attackers exploit.

  • A. Correct.

    Correct. Packet normalization, fragment reassembly, and validation of malformed or suspicious fragments are standard countermeasures against IDS/firewall evasion. Attackers often use tiny fragments, overlapping fragments, or unusual packet constructions so intermediate devices inspect incomplete data while the endpoint reconstructs the original payload. Reassembling traffic before inspection and dropping malformed fragments helps ensure the security device evaluates the same stream the destination host will process.

  • B. Incorrect.

    Incorrect. Disabling stateful inspection weakens the firewall and makes evasion easier, not harder. Stateful inspection helps track sessions and validate packet behavior across flows. Forwarding fragments without proper normalization increases the chance that the IDS and endpoint interpret traffic differently.

  • C. Incorrect.

    Incorrect. Increasing alert thresholds addresses noise, not protocol ambiguity or fragmentation-based evasion. If the IDS cannot properly reconstruct the packet stream, reducing sensitivity will likely make detection worse. The core problem is inspection fidelity, not alert volume.

  • D. Incorrect.

    Incorrect. Host-based antivirus can detect some malicious content after delivery, but it is not the primary countermeasure for network-layer fragmentation and flag-based evasion. This option reflects a common misconception that endpoint protection compensates for weak network inspection. Defense in depth is useful, but the direct mitigation is to normalize and reassemble traffic at the inspection point.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam