712-50 exam dumps

712-50 practice question 299 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 299

Select 2Understand perimeter defense systems such as grid sensors and access control lists on routers, firewalls, and other network devices

A global manufacturer is redesigning its Internet edge after several incidents in which reconnaissance traffic reached exposed services before the security operations center could investigate. The CISO wants a cost-effective perimeter improvement that both reduces unnecessary traffic at the earliest possible point and increases visibility into hostile scanning patterns across multiple sites. Which TWO actions should the CISO prioritize?

  1. A

    Implement ingress and egress access control lists (ACLs) on border routers to drop unauthorized or clearly invalid traffic before it reaches downstream firewalls

  2. B

    Deploy distributed grid sensors at key perimeter and DMZ network segments to collect and correlate reconnaissance and attack telemetry across sites

  3. C

    Replace firewall rules with router ACLs because ACLs provide equivalent application-layer inspection with lower latency

  4. D

    Configure the perimeter firewalls to allow any outbound traffic so grid sensors can learn normal behavior without policy bias

  5. E

    Rely on host-based antivirus logs from Internet-facing servers as the primary control for detecting perimeter reconnaissance

Show answer and explanation

Correct answers: A, B

Explanation

The best answer is to combine preventive filtering at the earliest feasible point with broader monitoring across the attack surface. Border router ACLs provide efficient, coarse-grained filtering that can block clearly unauthorized traffic and reduce unnecessary processing by firewalls and servers. Distributed grid sensors add detection and correlation capability, helping the organization identify scanning and reconnaissance trends across sites and DMZs. This reflects a defense-in-depth model rather than dependence on any single device type. Industry best practices from sources such as NIST guidance on boundary protection and network security architecture support layered controls at the perimeter, including boundary filtering, monitoring, and centralized analysis of security telemetry. Firewalls remain essential for stateful and application-aware enforcement, while router ACLs and sensors serve complementary roles rather than replacements.

  • A. Correct.

    Correct. Router ACLs are a practical first-line perimeter defense for enforcing basic traffic filtering close to the network edge. They can block unauthorized source/destination combinations, deny obviously illegitimate traffic, and help reduce load on downstream security devices. This aligns with defense-in-depth and with common network security architecture practices in which coarse filtering is performed as early as possible.

  • B. Correct.

    Correct. Grid sensors are useful for distributed visibility because they can observe traffic patterns across multiple locations and help correlate scanning, probing, and other reconnaissance activity that may not be obvious from a single device's logs. For a CISO concerned with earlier detection and cross-site situational awareness, strategically placed sensors at the perimeter and DMZ provide valuable telemetry without replacing preventive controls.

  • C. Incorrect.

    Incorrect. Router ACLs do not provide the same capabilities as stateful or next-generation firewalls. ACLs are generally limited to packet filtering based on fields such as IP addresses, protocols, and ports; they do not inherently offer equivalent application-layer inspection, session awareness, user context, or advanced threat controls. Choosing this option reflects the common misconception that all filtering technologies are functionally interchangeable.

  • D. Incorrect.

    Incorrect. Allowing any outbound traffic weakens egress control and increases the risk of data exfiltration, command-and-control communication, and misuse of internal systems. Grid sensors should complement policy enforcement, not justify weakening it. Best practice is to maintain risk-based outbound filtering and monitoring together.

  • E. Incorrect.

    Incorrect. Host-based antivirus logs may contribute useful endpoint telemetry, but they are not a primary perimeter control for detecting reconnaissance against the organization's Internet edge. Reconnaissance often occurs before malware execution and may target network infrastructure or exposed services directly. Relying mainly on endpoint antivirus would leave significant blind spots at the perimeter.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam