Network Security and Defense Questions

Securing networks at the infrastructure layer. Covers firewalls, ACLs and rule design, network device hardening and secure configuration, intrusion detection and prevention systems, VPN and remote-access encryption, network protocols and their security properties, and packet-level traffic analysis. The hands-on network-defense layer, distinct from zero-trust architecture strategy.

HardTechnical
36 practiced

Describe how you would create and run reproducible tests to evaluate an IDS's resilience to advanced evasion techniques such as overlapping IP fragments, malformed or unusual TCP options, and segmented HTTP payloads. Include test generation tools (Scapy, fragroute, tcpreplay), lab topology setup (mirrors and controlled endpoints), expected sensor failure modes, and remediation steps both at the sensor configuration level and host hardening.

EasyTechnical
21 practiced

List and briefly explain common IDS evasion techniques such as IP fragmentation, packet reordering, payload encoding/obfuscation, polymorphism, encryption/TLS, and protocol ambiguity. For each technique describe why it can bypass signature detection and a general mitigation approach or configuration setting to reduce risk.

That is every published Network Security and Defense question for Penetration Tester so far. Browse the other topics in this category, or practice this one interactively.