
EC-CouncilCertified Security Specialist
Domain 1Objective 5
Technical Controls (firewalls, IDS/IPS, VPNs, SIEM) ECSS Practice Questions (Page 2)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
14concepts
Questions 6–10
- 6
A security team wants to monitor traffic between the internal network and the DMZ to detect attacks that originate from compromised internal hosts. They also want to avoid introducing a point of failure that could disrupt traffic if the monitoring device fails. Which deployment approach best meets these requirements?
Select an answer first - 7
How does an IDS typically monitor network traffic?
Select an answer first - 8
In a remote-access VPN architecture, what does the client software typically do?
Select an answer first - 9
In the context of VPNs, what does 'tunneling' refer to?
Select an answer first - 10
What is a key characteristic of a stateful inspection firewall compared to a packet filtering firewall?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.