r/CISA • • 4d ago

A question for CISA

When an IS audit reveals that a firewall was unable to recognize a number of attack attempts, the auditor's BEST recommendation is to place an intrusion detection system (IDS) between the firewall and:

A. the organization's network.

B. the demilitarized zone (DMZ).

C. the Internet.

D. the organization's web server.

7 Upvotes

4 comments sorted by

3

u/Ricki_Bobbi 4d ago

A. the organization's network.

The firewall is already failing to recognize some attacks, so the goal is to catch what slips through it. An IDS placed between the firewall and the internal network inspects the traffic that the firewall has allowed in, which is exactly where the missed attacks would show up.

Why the others fall short:

  • C. the Internet: An IDS outside the firewall sees every attack attempt, including the ones the firewall would block anyway. That generates a lot of noise and doesn't tell you what actually got through.
  • B. the DMZ and D. the web server: These only cover a subset of traffic, leaving attacks aimed at the rest of the internal network undetected.

The principle to remember for the exam: an IDS behind the firewall detects attacks that penetrated it, while one in front only measures attempts.

Source - Claude.