ISO/IEC 27033-2:2012 - Network Security Design and Implementation Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Considering the principles of network segmentation and defense-in-depth as advocated by ISO/IEC 27033-2, where would be the most strategically advantageous location for an Intrusion Detection and Prevention System (IDPS) to monitor traffic between distinct internal network segments, such as between a development environment and a production server farm, to mitigate the risk of lateral movement by an advanced persistent threat that has already breached the perimeter?

Positioned to inspect traffic flowing between the development segment and the production server farm, as well as between different internal server subnets.
Deployed exclusively at the network perimeter, inspecting all inbound and outbound traffic to the organization's external interface.
Integrated solely within the server hardware of the production farm, monitoring only traffic directed to those specific servers.
Situated only on the network segment dedicated to end-user workstations, focusing on traffic originating from or destined for those devices.

About the ISO/IEC 27033-2:2012 - Network Security Design and Implementation Professional Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27033-2:2012 - Network Security Design and Implementation Professional exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.