Question 1 of 30
Considering the principles of network segmentation and defense-in-depth as advocated by ISO/IEC 27033-2, where would be the most strategically advantageous location for an Intrusion Detection and Prevention System (IDPS) to monitor traffic between distinct internal network segments, such as between a development environment and a production server farm, to mitigate the risk of lateral movement by an advanced persistent threat that has already breached the perimeter?
Positioned to inspect traffic flowing between the development segment and the production server farm, as well as between different internal server subnets.
Deployed exclusively at the network perimeter, inspecting all inbound and outbound traffic to the organization's external interface.
Integrated solely within the server hardware of the production farm, monitoring only traffic directed to those specific servers.
Situated only on the network segment dedicated to end-user workstations, focusing on traffic originating from or destined for those devices.

Preparing for ISO/IEC 27033-2:2012 - Network Security Design and Implementation Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free