Lecture 10 Pt. 2 Flashcards
Organizations may switch to a stanadlone NGIPS appliance if their firewall lacks _____ c___________
NGIPS capabilities
Scenarios include passive, inline without blocking, and inline with blocking.
What performance issue often arises when enabling security applications on NGFW?
Throughput degradation/increased latency.
How does separating the NGFW and NGIPS affect throughput and security?
It optimizes throughput and security
What capabilities does NGIPS provide for network resiliency based on the chosen hardware and deployment? (Fail-_____)*3
NGIPS can fail-open (taffic passes through logically), fail-closed (block all traffic), or fail-to-wire (traffic passes through physically, the device becomes a wire).
Fail Open may still involve software or OS-level logic, Fail-to-wire sends traffic as electrical signals
What can lead to conflict in an enterprise regarding NetOps and SecOps?
Using a single appliance for the NGFW and NGIPS
Conflicts may arise if both operations are combined without clear delineation.
An IPS will typically operate in the same Network location as the firewall, but where is it generally positioned?
After the firewall, closer to the interior or private network.
The primary function of an IDS is to ______ potential _______ and generate _______
detect; threats; alerts.
Who is a leader in NGIPS technology?
Cisco.
Cisco offers Firepower NGIPS products for protection against evolving attack surfaces.
What is the basis of the Cisco Firepower NGIPS engine?
Well-defined open source Snort.
Snort is a widely used intrusion detection and prevention system.
What does SRU stand for in the context of Cisco NGIPS?
Snort Rules Updates.
SRUs contain the latest Snort rules and are released regularly for updates.
How often are Snort Rules Updates (SRUs) released?
On Tuesday and Thursday, with out-of-band releases for critical updates.
Each SRU includes a complete rule set.
What is the role of the Cisco Talos team?
Developing Cisco Snort IPS rules.
The team also ensures that rules are open for inspection and sourced from various inputs.
Throughput issues on a NGIPS/NGFW combination system can be alleviated by:
Switching to a standalone NGIPS system
Issue with combination firewalls: Mandatory ________ m____ and performance may exceed firewall capabilities
Mandatory blocking mode
Mandatory blocking: All suspicious traffic must be blocked
Is a NGFW/NGIPS combination adequate for the segregation of NetOps and SecOps responsibilities?
No, ideally they should be separated
T/F - You must prepare a fault-tolerance solution within a SPAN or TAP deployment
False
T/F - You must prepare a fault-tolerance solution within an inline deployment
True. Fail-open, Fail-closed, or Fail-to-wire
You ideally want the _________ to filter out non-legitimate traffic before the ___ analyzes the traffic flow