During a security test, after an external DoS attack, an FTP session from an external IP to the internal network succeeds. What happened to the firewall?

Enhance your knowledge as a Computer Hacking Forensic Investigator with the CHFI v11 Test. Use flashcards and multiple-choice questions, complete with hints and detailed explanations, to prepare effectively and ace your exam!

Multiple Choice

During a security test, after an external DoS attack, an FTP session from an external IP to the internal network succeeds. What happened to the firewall?

Explanation:
The test hinges on how firewalls behave when they fail. If a firewall fails-open, it stops filtering and lets traffic pass as if there were no barrier at all. Seeing an FTP session from an external IP into the internal network succeed after an external DoS attack fits this scenario: the firewall didn’t block the connection as it should, so traffic got through. A fail-closed state would block such traffic, so the session wouldn’t succeed. Purging ACLs could also lead to less filtering, but the key point here is the device’s failure mode during the DoS event, which is best described as failing open. A failed-bypass would imply a separate bypass mechanism rather than a general open state caused by a fault.

The test hinges on how firewalls behave when they fail. If a firewall fails-open, it stops filtering and lets traffic pass as if there were no barrier at all. Seeing an FTP session from an external IP into the internal network succeed after an external DoS attack fits this scenario: the firewall didn’t block the connection as it should, so traffic got through. A fail-closed state would block such traffic, so the session wouldn’t succeed. Purging ACLs could also lead to less filtering, but the key point here is the device’s failure mode during the DoS event, which is best described as failing open. A failed-bypass would imply a separate bypass mechanism rather than a general open state caused by a fault.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy