712-50 exam dumps

712-50 practice question 290 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 290

Select 3Firewall, IDS/IPS and Network Defense Systems (5 questions)

A global company is migrating several customer-facing applications to a hybrid architecture, with web servers in a public cloud and core databases remaining on-premises. During a recent incident review, the CISO learned that a misconfigured cloud security group exposed an administrative service to the internet for several hours before being detected. The board has asked for a network defense strategy that reduces the likelihood and impact of similar exposure events while maintaining business availability and minimizing manual rule administration across environments. Which TWO actions should the CISO prioritize as part of the target-state architecture?

  1. A

    Implement a default-deny segmentation model between tiers, allowing only explicitly approved flows between internet, web, application, and database zones

  2. B

    Rely primarily on signature-based IDS sensors at the internet edge, because they can detect most unauthorized exposure issues without affecting traffic flow

  3. C

    Deploy IPS or equivalent preventive controls inline at key trust boundaries and integrate firewall policy management with centralized change control and rule review

  4. D

    Permit administrative access from any source IP as long as multi-factor authentication is enabled, since identity controls compensate for network exposure

  5. E

    Standardize hardened baselines for cloud security groups and on-premises firewalls, with continuous monitoring to detect rule drift and unauthorized changes

Show answer and explanation

Correct answers: A, C, E

Explanation

The strongest executive-level answer focuses on layered network defense and governance rather than a single device or control. In this scenario, the organization needs to reduce accidental exposure in a hybrid environment while preserving availability and minimizing manual rule sprawl. The best priorities are: (1) default-deny segmentation to limit reachable services and lateral movement, (3) preventive controls such as IPS at key boundaries combined with centralized firewall policy governance, and (5) hardened baselines with continuous monitoring for configuration drift across cloud and on-premises platforms.

Option 2 is insufficient because IDS alone is primarily detective and does not address policy misconfiguration risk. Option 4 reflects a common misconception that strong authentication can replace network restrictions; in reality, privileged services should be tightly scoped and not broadly exposed.

These choices are consistent with widely accepted guidance, including NIST SP 800-41 on firewalls and firewall policy, NIST SP 800-53 controls such as SC-7 (boundary protection) and CM-related controls for configuration management, and zero trust principles described in NIST SP 800-207. CIS Benchmarks and vendor best practices for cloud security groups similarly emphasize least privilege, restricted administrative access, and continuous monitoring for unauthorized policy changes.

  • A. Correct.

    Correct. A default-deny, least-privilege segmentation model is a foundational network defense practice. In a hybrid environment, limiting allowed traffic to only required flows between defined zones significantly reduces lateral movement and the blast radius of misconfigurations. For example, a temporary exposure of an administrative service is less damaging when management access is isolated and not broadly reachable across zones. This aligns with zero trust and network segmentation best practices.

  • B. Incorrect.

    Incorrect. Signature-based IDS at the edge can help identify known attack patterns or suspicious traffic, but IDS is detective rather than preventive unless coupled with active blocking. It also does not solve the root issue of overexposed services or poor policy governance. Unauthorized exposure is often best mitigated through hardened access policies, segmentation, preventive controls, and continuous configuration monitoring rather than relying mainly on IDS alerts.

  • C. Correct.

    Correct. Inline IPS or equivalent preventive inspection at important trust boundaries can block exploit attempts and policy-violating traffic in real time, complementing firewalls. Equally important at the executive level is centralized policy governance: integrating firewall policy management with formal change control, review, and recertification reduces ad hoc rules, improves consistency across cloud and on-premises environments, and supports auditability. This is a practical control combination for reducing both likelihood and impact.

  • D. Incorrect.

    Incorrect. MFA is valuable, but it does not justify exposing administrative interfaces to any source IP. Internet-exposed management services increase attack surface, facilitate brute-force and vulnerability exploitation attempts, and create unnecessary risk even when identity controls are present. Best practice is to restrict administrative access by network location, bastion hosts, VPN/ZTNA, or privileged access paths in addition to MFA.

  • E. Correct.

    Correct. Standardized secure baselines for cloud security groups and traditional firewalls help enforce consistency and reduce configuration errors. Continuous monitoring for drift, unauthorized changes, and policy violations is especially important in hybrid environments where changes may occur rapidly through consoles, APIs, or infrastructure-as-code pipelines. This directly addresses the incident scenario by improving both prevention and detection of accidental exposure.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam