712-50 exam dumps

712-50 practice question 298 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 298

Single answerUnderstand perimeter defense systems such as grid sensors and access control lists on routers, firewalls, and other network devices

A global manufacturing company is preparing for a high-profile product launch and expects a significant increase in internet traffic to its public web applications. The CISO learns from threat intelligence that competitors and hacktivists may attempt reconnaissance and low-volume attacks designed to bypass signature-based controls. The company already has perimeter firewalls and router ACLs, but leadership wants earlier visibility into suspicious activity without disrupting legitimate customer traffic. Which action should the CISO prioritize to BEST improve perimeter detection while preserving existing access paths?

  1. A

    Deploy grid sensors at key ingress and egress network segments to monitor traffic patterns and correlate suspicious activity across the perimeter, while keeping firewall and router ACL policies aligned to authorized flows

  2. B

    Replace router ACLs with broad permit rules so grid sensors can inspect all traffic without interference, then rely on the sensors to block malicious packets in real time

  3. C

    Disable firewall logging during the launch window to reduce device overhead, and depend on router ACL counters as the primary source of attack detection

  4. D

    Move all perimeter filtering from firewalls to internal switches so suspicious activity can be identified closer to the application servers

Show answer and explanation

Correct answer: A

Explanation

The best choice is to add visibility through grid sensors at strategic ingress and egress points while maintaining strong preventive controls on routers and firewalls. In real-world perimeter defense, ACLs on routers and policy rules on firewalls are preventive mechanisms used to restrict traffic to authorized flows. Sensors complement them by improving detection and correlation across distributed network locations, which is especially valuable for identifying reconnaissance, low-and-slow attacks, and suspicious patterns that may not be blocked immediately by static rules alone.

This aligns with common security architecture guidance from NIST and CIS: use layered defenses, maintain least functionality/least access at network boundaries, and centralize or correlate monitoring data for timely detection. Relevant references include NIST SP 800-41 on firewalls and firewall policy, NIST SP 800-94 on intrusion detection and prevention concepts, and the CIS Critical Security Controls guidance on network monitoring and boundary defense. From a CCISO perspective, the decision is not merely technical; it is risk-based and operationally practical: improve detection coverage during a high-risk business event without unnecessarily disrupting legitimate customer traffic or weakening existing perimeter enforcement.

  • A. Correct.

    Correct. Grid sensors are used to improve visibility across multiple network vantage points and can help identify reconnaissance, scanning, and distributed low-volume attacks that may not trigger simple signature-based controls. Keeping existing firewall and router ACL rules aligned to approved traffic preserves legitimate business access while adding monitoring depth. This reflects defense-in-depth and layered perimeter security rather than replacing established controls.

  • B. Incorrect.

    Incorrect. Router ACLs should not be replaced with broad permit rules just to increase visibility. That would weaken a core preventive control at the perimeter and unnecessarily expand exposure. In addition, sensors are generally for monitoring, detection, and analysis; they are not a direct substitute for properly configured firewall or router enforcement. This option reflects the misconception that detection tools can replace preventive filtering.

  • C. Incorrect.

    Incorrect. Disabling firewall logging reduces situational awareness precisely when the organization expects heightened threat activity. Router ACL counters can provide limited information, but they do not replace the richer telemetry and event detail available from firewalls and monitoring systems. This option is attractive to those concerned about performance, but best practice is to tune logging appropriately, not eliminate it during a high-risk period.

  • D. Incorrect.

    Incorrect. Internal switches are not a replacement for perimeter firewalls and router ACLs. Moving perimeter filtering inward delays enforcement and allows more unwanted traffic into the environment before inspection or rejection. This contradicts the principle of filtering as close to the source or boundary as practical and weakens the organization's perimeter defense posture.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam