Lecture 10 Pt. 2 Flashcards

1
Q

Organizations may switch to a stanadlone NGIPS appliance if their firewall lacks _____ c___________

A

NGIPS capabilities

Scenarios include passive, inline without blocking, and inline with blocking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What performance issue often arises when enabling security applications on NGFW?

A

Throughput degradation/increased latency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does separating the NGFW and NGIPS affect throughput and security?

A

It optimizes throughput and security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What capabilities does NGIPS provide for network resiliency based on the chosen hardware and deployment? (Fail-_____)*3

A

NGIPS can fail-open (taffic passes through logically), fail-closed (block all traffic), or fail-to-wire (traffic passes through physically, the device becomes a wire).

Fail Open may still involve software or OS-level logic, Fail-to-wire sends traffic as electrical signals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What can lead to conflict in an enterprise regarding NetOps and SecOps?

A

Using a single appliance for the NGFW and NGIPS

Conflicts may arise if both operations are combined without clear delineation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An IPS will typically operate in the same Network location as the firewall, but where is it generally positioned?

A

After the firewall, closer to the interior or private network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The primary function of an IDS is to ______ potential _______ and generate _______

A

detect; threats; alerts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who is a leader in NGIPS technology?

A

Cisco.

Cisco offers Firepower NGIPS products for protection against evolving attack surfaces.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the basis of the Cisco Firepower NGIPS engine?

A

Well-defined open source Snort.

Snort is a widely used intrusion detection and prevention system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does SRU stand for in the context of Cisco NGIPS?

A

Snort Rules Updates.

SRUs contain the latest Snort rules and are released regularly for updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How often are Snort Rules Updates (SRUs) released?

A

On Tuesday and Thursday, with out-of-band releases for critical updates.

Each SRU includes a complete rule set.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the role of the Cisco Talos team?

A

Developing Cisco Snort IPS rules.

The team also ensures that rules are open for inspection and sourced from various inputs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Throughput issues on a NGIPS/NGFW combination system can be alleviated by:

A

Switching to a standalone NGIPS system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Issue with combination firewalls: Mandatory ________ m____ and performance may exceed firewall capabilities

A

Mandatory blocking mode

Mandatory blocking: All suspicious traffic must be blocked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is a NGFW/NGIPS combination adequate for the segregation of NetOps and SecOps responsibilities?

A

No, ideally they should be separated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

T/F - You must prepare a fault-tolerance solution within a SPAN or TAP deployment

17
Q

T/F - You must prepare a fault-tolerance solution within an inline deployment

A

True. Fail-open, Fail-closed, or Fail-to-wire

18
Q

You ideally want the _________ to filter out non-legitimate traffic before the ___ analyzes the traffic flow