exam questions

Exam CS0-001 All Questions

View all questions & answers for the CS0-001 exam

Exam CS0-001 topic 1 question 60 discussion

Actual exam question from CompTIA's CS0-001
Question #: 60
Topic #: 1
[All CS0-001 Questions]

The new Chief Technology Officer (CTO) is seeking recommendations for network monitoring services for the local intranet. The CTO would like the capability to monitor all traffic to and from the gateway, as well as the capability to block certain content. Which of the following recommendations would meet the needs of the organization?

  • A. Recommend setup of IP filtering on both the internal and external interfaces of the gateway router.
  • B. Recommend installation of an IDS on the internal interface and a firewall on the external interface of the gateway router.
  • C. Recommend installation of a firewall on the internal interface and a NIDS on the external interface of the gateway router.
  • D. Recommend installation of an IPS on both the internal and external interfaces of the gateway router.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
slcc99
Highly Voted 5 years ago
This question was in the exam :)
upvoted 8 times
...
Reem01
Highly Voted 4 years, 7 months ago
Due to the requirements provided, you should install a NIPS on the internal interface of the gateway router and a firewall on the external interface of the gateway router. The firewall on the external interface will allow the bulk of the malicious inbound traffic to be filtered prior to reaching the network. Then, the NIPS can be used to conduct an inspection of the traffic entering the network and provide protection for the network using signature-based or behavior-based analysis. A NIPS is less powerful than a firewall and could easily "fail open" if it is overcome with traffic by being placed on the external interface.
upvoted 5 times
...
Jeend
Most Recent 2 years, 3 months ago
From Jason Dion: “In order to meet the requirement to monitor all traffic to and from the network’s gateway, it is best to utilize a network intrusion detection system (NIDS) that monitors the external interface of the gateway router. In order to be able to block certain types of content, it is best to install a firewall on the internal interface, where ACLs can be established for those traffic types”
upvoted 2 times
mhop321
2 years, 2 months ago
Why have you put a blatant lie on here? The Jason Dion CYSA+ exams has this question and the answer is B - IDS is internal to monitor traffic, firewall is external.
upvoted 2 times
...
...
Chiaretta
3 years, 2 months ago
The right one is B. IDS monitor the internal network and firewall monitor the traffic in and out the gateway and possibly filter traffic.
upvoted 1 times
...
SecurityDude
4 years, 2 months ago
I am going D on this one, IPS blocks where IDS only monitors
upvoted 1 times
...
Acrisius
4 years, 4 months ago
I would suggest B. Firewall blocks most unwanted traffic from getting in. IDS would pickup any stragglers. Similar Q in 002
upvoted 1 times
...
0xff
4 years, 6 months ago
The answer should be D. The keyword being "content" from the sentence "... as well as the capability to block certain CONTENT". Firewalls do not have the capbility to block specific content. "An IPS will inspect content of the request and be able to drop, alert, or potentially clean a malicious network request based on that content" "A firewall will block traffic based on network information such as IP address, network port and network protocol." Source: https://its.umich.edu/enterprise/wifi-networks/network-security/ips-vs-firewalls
upvoted 3 times
...
kkarri
4 years, 6 months ago
It should be B. You can put sensors of both NIPS or NIDS on the external interface of the router because that would cause latency in traffic and could get both NIPS and NIDS down due to high traffic. see the link for the proper architecture : https://www.researchgate.net/figure/Generic-architecture-of-a-network-based-IDS-NIDS-The-operational-structure-of-a-NIDS_fig3_329394492
upvoted 2 times
kkarri
4 years, 6 months ago
you can't*
upvoted 2 times
...
...
Toyeeb
4 years, 8 months ago
"The CTO would like the capability to monitor all traffic to and from the gateway, as well as the capability to block certain content." The key part of the question is stated above. A solution that can monitor and block both internally and externally in which only option D satisfies.
upvoted 1 times
...
MagicianRecon
4 years, 9 months ago
B should be a better answer. CTO wants monitoring for traffic to and from local gateway and block certain external traffic
upvoted 2 times
...
G59
4 years, 9 months ago
D. Recommend installation of an IPS on both the internal and external interfaces of the gateway router.
upvoted 2 times
...
shoop
4 years, 11 months ago
definitely C, as to see ALL traffic coming in from the outside, the IDS would have to be placed before the firewall (otherwise some traffic would be blocked)
upvoted 2 times
Blind_Hatred
4 years, 10 months ago
But TO and FROM the gateway would not be limited to traffic on the external interface? You would also want to see traffic going TO and FROM the gateway on the internal interface, right?
upvoted 1 times
...
...
s3curity1
4 years, 11 months ago
Is this really C? or B? Can anyone explain? Thanks
upvoted 1 times
XAmbivert
4 years, 8 months ago
"NIDS is often placed in front of a firewall, where it detect attacks and anomalies and alerts the admin. The firewall does its best to prevent those attacks from entering the network. A NIDS can also be placed behind a firewall or several NIDS can be strategically placed throughout the network. When a NIDS is in front of the firewall, it generates more alerts but these can be whittled down on the NIDS." David Prowse Certificate Guide Sec+ The answer would be C, to enable the admin monitor all to and fro traffic, and block certain content.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago