7.7 Detection & Preventive Security Controls

CISSP Domain 7 ยท Security Operations

7.7 Detection & Preventive Security Controls

Security controls are valuable only when they continue to work in the environment they are protecting.

Firewalls need appropriate rules. Intrusion-detection systems need useful signatures and tuning. Anti-malware engines need current intelligence. Sandboxes need to recognise suspicious behaviour. Security services need monitoring and oversight.

CISSP 7.7 therefore focuses not simply on installing security technology, but on operating, maintaining, tuning and validating controls that detect or prevent malicious activity.

๐Ÿ›ก๏ธ

Prevent

Stop unwanted activity before it reaches or affects the protected asset.

STOP IT
๐Ÿ”Ž

Detect

Identify suspicious or malicious behaviour that still occurs.

SEE IT
โš™๏ธ

Maintain

Keep controls healthy, current, appropriately configured and tuned.

KEEP IT EFFECTIVE
Current CISSP 7.7 Scope

Operate and Maintain Detection and Preventative Measures

The current CISSP Exam Outline explicitly includes:

Firewalls

Including next-generation, web application and network firewalls.

IDS & IPS

Intrusion Detection Systems and Intrusion Prevention Systems.

Whitelisting / Blacklisting

Permit known or approved entities and block known unwanted entities.

Third-Party Security Services

Detection or preventive capabilities delivered by external providers.

Sandboxing

Execute suspicious or untrusted content within a restricted environment.

Honeypots / Honeynets

Deceptive resources designed to attract or reveal suspicious activity.

Anti-Malware

Detect, prevent, quarantine or otherwise control malicious software.

Machine Learning & AI-Based Tools

Use data-driven models to identify, classify or prioritise suspicious behaviour.

7.7 Official Topics

FILTER Firewalls
DETECT / BLOCK IDS / IPS
ALLOW / DENY Lists
OUTSOURCE Security services
ISOLATE Sandbox
DECEIVE Honeypot
SCAN Anti-malware
LEARN ML / AI

The Big Idea

Detection and prevention are complementary.

Threat โ†’ Preventive Control
Prevented โ†’ Attack Stopped
Not Prevented โ†’ Detective Control
Detected โ†’ Investigation / Response
Prevention tries to stop the activity. Detection tells you that activity occurred or is occurring.

Defensive Model

PREVENT Stop
DETECT Discover
RESPOND Act
TUNE Improve
Control Functions

Preventive vs Detective

Preventive Control

Attempts to stop an unwanted action from succeeding.

Firewall Deny Rule IPS Block Application Allowlisting Anti-Malware Prevention

STOP IT

Detective Control

Identifies potentially unwanted activity so it can be investigated or acted upon.

IDS Alert Honeypot Alert Malware Detection AI Anomaly Detection

FIND IT

One technology can perform several functions

An anti-malware product may detect malware and then prevent execution. An IPS can detect an attack and automatically block it.

Classify the CONTROL ACTION, not merely the product name.
๐Ÿ”— 7.2 vs 7.7 Why does IDS/IPS appear in both?
7.2 Logging & Monitoring

Focuses on monitoring activities and the information used to detect security events.

SIEM Logs Threat Intelligence UEBA Monitoring
7.7 Detection & Prevention

Focuses on operating and maintaining the protective and detective technologies themselves.

Firewall IDS / IPS Sandbox Anti-Malware Honeypot
7.2 = observe the environment. 7.7 = operate the controls doing much of the observing and blocking.

Defence in Depth

No single detection or preventive mechanism should be expected to stop every attack.

Internet โ†’ Network Firewall
Web Traffic โ†’ WAF
Network Behaviour โ†’ IDS / IPS
Endpoint โ†’ Anti-Malware / EDR
Unknown File โ†’ Sandbox
Unexpected Activity โ†’ AI / Behaviour Detection
One control misses. Another control may still detect.
Official 7.7 Topic 1

Firewalls

A firewall controls network communication according to security policy.

It can permit required traffic while rejecting communications that should not cross a security boundary.

Traffic โ†’ Firewall Policy
Permitted โ†’ Allow
Not Permitted โ†’ Deny
Important Activity โ†’ Log / Alert

Firewall

TRAFFIC Arrives
POLICY Evaluates
ALLOW / DENY Enforces
LOG Records

Firewall Types

Packet-Filtering Firewall

Makes decisions using information such as source, destination, protocol and port.

Stateful Firewall

Maintains awareness of connection state when evaluating traffic.

Application / Proxy Firewall

Can inspect and mediate communications at higher protocol layers.

Next-Generation Firewall - NGFW

Commonly combines traditional firewall functions with deeper traffic, application and threat inspection capabilities.

Web Application Firewall - WAF

Protects web applications by inspecting HTTP/HTTPS application traffic.

Host-Based Firewall

Controls traffic entering or leaving an individual host.

๐ŸŒ Network Firewall vs WAF Different layers and different questions
Network Firewall

Typically asks:

Should this network communication be permitted?

IP Address Port Protocol Connection
Web Application Firewall

Typically asks:

Does this HTTP request appear appropriate for the web application?

URL HTTP Method Headers Parameters Application Payload
Example

Network firewall permits: TCP 443.

WAF then identifies: a malicious request inside the permitted HTTPS service.

Network firewall protects the network path. WAF understands the web application conversation.
๐Ÿ”ฅ Next-Generation Firewall Firewall functionality combined with richer inspection and threat controls

NGFW implementations may combine capabilities such as:

Stateful Inspection Application Awareness User Awareness IDS / IPS URL Filtering Threat Intelligence Malware Inspection TLS Inspection
NGFW โ‰  automatically secure configuration

Advanced features provide little benefit if rules are overly broad, unused or poorly maintained.

Firewall Policy

Default Deny

A strong firewall policy commonly permits traffic that is explicitly required and denies traffic that is not authorised.

Business Requirement โ†’ Specific Allow Rule
Everything Else โ†’ Deny
Better rule

Application servers:

may connect to database servers on the required database port.

Weak rule

Application network:

ANY โ†’ ANY โ†’ ANY.

Permit what is required. Deny what is not.

Ingress & Egress Filtering

Ingress

Controls traffic entering a network or security zone.

WHAT MAY COME IN?

Egress

Controls traffic leaving a network or security zone.

WHAT MAY GO OUT?

Compromised server

Malware attempts to connect to: an attacker-controlled command-and-control server.

Appropriate egress filtering may: block or reveal the connection.

Traffic Direction

INGRESS Coming in
EGRESS Going out
Operate & Maintain

Firewall Rule Lifecycle

Firewall security is not finished when a rule is created.

Request โ†’ Business Need
Assess โ†’ Risk + Scope
Approve โ†’ Authorised Rule
Implement โ†’ Controlled Change
Test โ†’ Works as Intended
Monitor โ†’ Usage + Logs
Review โ†’ Still Needed?
Retire โ†’ Remove Unneeded Rule
Firewall rules should have a reason to exist and should stop existing when the reason disappears.
๐Ÿงน Firewall Rule Problems Rules accumulate over time
Overly Broad Rule

Allows more systems, protocols or destinations than required.

Temporary Rule

Created for troubleshooting and never removed.

Unused Rule

Supports a system or service that no longer exists.

Shadowed Rule

Another earlier rule causes the intended rule never to be reached.

Duplicate Rule

Multiple rules perform the same function unnecessarily.

Misordered Rule

Rule order causes unexpected policy behaviour.

Firewall rule review is part of firewall security.
Official 7.7 Topic 2

IDS vs IPS

Intrusion Detection System - IDS

Monitors activity and identifies signs of potentially malicious behaviour.

Typically: alerts.

DETECTIVE

Intrusion Prevention System - IPS

Includes detection capability and can also attempt to stop identified malicious activity.

Typically: alerts + blocks.

DETECTIVE + PREVENTIVE

IDS vs IPS

IDS I Detect Something
IPS I Prevent Something
๐Ÿšฆ Passive vs Inline Where the control sits changes what it can do
Passive Monitoring

Receives or observes a copy of traffic.

Common IDS approach.

Detection can occur without being directly in the traffic path.

Inline Enforcement

Traffic passes through the security control.

Common IPS approach.

The device can directly allow, drop or modify traffic.

To block traffic directly, the control usually needs an enforcement position in the traffic path or another mechanism capable of taking action.

Network-Based vs Host-Based Detection

NIDS / NIPS

Monitors network communication.

Packets Flows Protocols Network Attacks
HIDS / HIPS

Operates on or closely monitors an individual host.

Processes Files System Calls Host Activity
Network sensors see network behaviour. Host sensors see activity on the host.
Detection Logic

Signature vs Anomaly / Behaviour Detection

Signature-Based

Looks for patterns associated with known malicious activity.

Strong for: known threats.

Anomaly / Behaviour-Based

Identifies activity that differs from expected behaviour or learned patterns.

Can help identify: previously unseen or unusual activity.

Detection Method

SIGNATURE Have I seen this pattern before?
ANOMALY Does this look unusual?
Essential CISSP Concept

True / False Positives & Negatives

RealityControl SaysResult
AttackAttackTrue Positive
NormalAttackFalse Positive
AttackNormalFalse Negative
NormalNormalTrue Negative

Detection Errors

FALSE POSITIVE Alarm but no attack
FALSE NEGATIVE Attack but no alarm
โš–๏ธ False Positive vs False Negative Both matter, but in different ways
Too Many False Positives

Analysts investigate harmless activity.

Alert Fatigue Wasted Time Lower Trust
False Negative

Real malicious activity passes undetected.

Threat Missed Incident Continues False Assurance
Tuning seeks useful detection - not simply the greatest possible number of alerts.

Detection Tuning

Deploy Detection โ†’ Observe Alerts
Investigate โ†’ True or False?
Too Noisy โ†’ Refine Logic
Missed Attack โ†’ Improve Coverage
Threat Changes โ†’ Update Detection
Detection is an operational capability, not a one-time installation.
Official 7.7 Topic 3

Whitelisting / Blacklisting

The CISSP Exam Outline currently uses the terms whitelisting and blacklisting.

In modern technical documentation you will also commonly see:

allowlisting and blocklisting / denylisting.

Allowlisting

Define what is authorised.

Everything else may be rejected.

KNOWN / APPROVED GOOD

Blocklisting / Denylisting

Define what is prohibited.

Everything else may remain permitted unless another control blocks it.

KNOWN BAD

Lists

ALLOWLIST Only these are allowed
BLOCKLIST These are denied
โœ… Application Allowlisting Permit approved software instead of trying to identify every bad program
Allowed
Approved Browser Office Applications Corporate VPN Approved Security Tools
Unknown executable

Not on approved list.

Result: execution blocked.

Allowlisting asks: "Why should this be allowed?"
โ›” Blocklisting Stop known unwanted entities

Blocklists may contain:

Malicious IP Addresses Domains URLs File Hashes Email Senders Applications
Threat intelligence

Known ransomware command-and-control domain:

added to security blocklist.

Blocklist โ‰  protection from unknown threats

An attacker can use infrastructure that is not yet known to be malicious.

Allowlisting vs Blocklisting

Allowlisting

Default: not allowed.

Permit: approved entities.

Stronger control where the permitted set is manageable.

Blocklisting

Default: generally allowed.

Deny: known unwanted entities.

Easier where legitimate possibilities are extremely broad.

Allowlist = known good. Blocklist = known bad.
โš™๏ธ Allowlisting Must Be Maintained A static approved list can become an operational problem
Software update

Approved application: Version 12.

Organisation deploys: Version 13.

Allowlist still recognises only: Version 12.

The control may now:

block legitimate business software.

Highly restrictive controls require good change and configuration management.
Official 7.7 Topic 4

Third-Party Provided Security Services

Organisations may outsource parts of their detection or prevention capability to specialist providers.

MSSP

Managed Security Service Provider supplying ongoing security technology or monitoring services.

MDR

Managed Detection and Response provider focused on detection, investigation and response support.

Cloud WAF / DDoS

Provider filters hostile web or volumetric traffic before it reaches organisational systems.

Email Security

Third party filters malicious email, attachments and links.

DNS Security

External service blocks or detects access to malicious domains.

Threat Intelligence

Provider supplies information about malicious infrastructure, campaigns or indicators.

Outsourcing the security service does not outsource organisational accountability for security risk.
๐Ÿค Questions for a Security Provider Who does what when something happens?
What Is Monitored? 24/7 or Business Hours? Who Investigates? Who Can Contain? How Quickly Are We Notified? What Logs Can We Access? How Long Is Data Retained? Who Owns the Rules? How Are Escalations Handled? What Happens at Contract End?
"We have an MDR provider" is not an incident-response process. Responsibilities must still be understood.

Service Levels Matter

Weak arrangement

Provider will: monitor security alerts.

Clearer arrangement

Provider monitors: 24 hours a day.

Critical alert: reviewed within 10 minutes.

Confirmed critical incident: customer notified through specified escalation path.

Detection outsourced without escalation defined can still leave the organisation blind at the moment that matters.
Official 7.7 Topic 5

Sandboxing

A sandbox provides a restricted environment in which untrusted or suspicious code can run with limited access to real system resources.

Unknown File โ†’ Sandbox
Execute โ†’ Observe Behaviour
Suspicious Behaviour โ†’ Block / Alert
Benign Behaviour โ†’ Policy Decision

Sandbox

ISOLATE Untrusted code
EXECUTE Safely
OBSERVE Behaviour
DECIDE Allow or block

What Might a Sandbox Observe?

File Changes

Does the program create, encrypt or delete files?

Process Creation

Does it launch suspicious child processes?

Network Connections

Does it contact suspicious external infrastructure?

Registry / Configuration

Does it modify system settings?

Persistence

Does it try to survive system restart?

Privilege Behaviour

Does it attempt elevation or access protected resources?

๐ŸŽญ Sandbox Evasion Malware may try to recognise that it is being analysed

Sophisticated malware can attempt to identify indicators of a sandbox and change its behaviour.

Example

Malware checks for:

Virtualisation Artifacts Analysis Tools No User Activity Very Short Runtime

If analysis is suspected, malware:

does nothing malicious.

Sandbox produced no malicious behaviour โ‰  file is guaranteed safe.
๐Ÿšช Sandbox Escape The isolation mechanism itself can have weaknesses

A sandbox must itself be securely designed and maintained.

If malicious code exploits the isolation technology, it may be able to:

Access Host Resources Escape Isolation Attack Other Systems
Isolation is a security control. Security controls can also contain vulnerabilities.
Official 7.7 Topic 6

Honeypots & Honeynets

Honeypot

A deceptive system or resource designed to appear attractive to an attacker.

ONE DECOY RESOURCE

Honeynet

A larger environment or collection of deceptive systems designed to appear like a real network.

NETWORK OF DECOYS

Deception

HONEYPOT Decoy system
HONEYNET Decoy network

Why Use Deception?

Early Detection

Legitimate users should have little reason to interact with the decoy.

Attacker Observation

Security teams may observe techniques used against the environment.

Threat Intelligence

Interaction can reveal tools, infrastructure and attacker behaviour.

Tripwire

Access to a deceptive resource can provide a high-value investigation signal.

Example

An internal server named:

PAYROLL-LEGACY-DB

exists only as a deception system.

A workstation begins authenticating to it unexpectedly.

Why is a real employee trying to access the fake payroll server?
๐Ÿฏ Related Concept: Honeytokens The decoy does not have to be an entire computer

Deception can also involve fake information or credentials designed to generate an alert if used.

Fake API Key Fake Database Record Fake Administrator Credential Decoy File Decoy Cloud Secret
Example

A fake credential is placed where: no legitimate process should ever use it.

Authentication occurs using that credential.

Result: high-value security signal.

โš ๏ธ Honeypots Need Isolation A compromised decoy should not become an attack platform

A honeypot intentionally attracts malicious activity.

If poorly isolated, an attacker could potentially use the compromised decoy to:

Attack Production Scan Other Systems Host Malware Attack External Targets
A decoy should observe the attacker without creating a new path into production.
Official 7.7 Topic 7

Anti-Malware

Anti-malware technologies identify and control malicious software such as viruses, worms, trojans, spyware, ransomware and other hostile code.

Signature Detection

Recognises known malicious patterns.

Heuristics

Looks for characteristics associated with malicious programs.

Behaviour Analysis

Watches what software actually does.

Reputation

Uses information about files, URLs, certificates or publishers.

Real-Time Protection

Inspects activity as files or processes are accessed or executed.

Quarantine

Isolates suspicious content to prevent normal use.

๐Ÿ’ป Traditional Anti-Virus vs Modern Endpoint Detection Modern endpoint protection commonly combines several techniques
Traditional Antivirus

Historically focused strongly on identifying known malware through signatures and scanning.

Modern Endpoint Protection / EDR

May combine:

Malware Prevention Behaviour Detection Process Telemetry Threat Hunting Endpoint Isolation Response Actions
Anti-malware detects malicious software. EDR provides broader endpoint detection and response capabilities.

Anti-Malware Must Stay Current

Threat Changes โ†’ New Detection Intelligence
Security Product โ†’ Update
Detection Engine โ†’ Current Coverage
A security agent running successfully does not mean its protection is current.
โค๏ธ Monitor Security Agent Health "Installed" is not the same as "protecting"
Installed?

Is the security agent present?

Running?

Is the service operational?

Current?

Are engine and detection updates current?

Connected?

Is the agent communicating with management systems?

Protected?

Are expected prevention features actually enabled?

Tampered?

Has protection been disabled or modified?

Control health should itself be monitored.
Attacker Behaviour

Security Controls Become Targets

Attackers may attempt to disable or bypass the very technologies designed to detect them.

Disable EDR Stop Antivirus Service Modify Firewall Rules Delete Logs Disable Sensors Tamper With Detection Configuration
Important detection

Endpoint security agent: unexpectedly stops on a production server.

A security control unexpectedly becoming unavailable can itself be a security event.
Official 7.7 Topic 8

Machine Learning & AI-Based Security Tools

Machine-learning and AI capabilities can analyse large volumes of security information and identify patterns that would be difficult to manage manually.

Anomaly Detection

Identify behaviour that differs from expected patterns.

Malware Classification

Analyse characteristics or behaviour of suspicious files.

User Behaviour

Identify unusual identity or access activity.

Network Behaviour

Detect unusual traffic patterns.

Alert Prioritisation

Help rank large numbers of alerts according to predicted risk.

Threat Correlation

Identify relationships across multiple signals.

Analyst Assistance

Help summarise or enrich security information.

Automated Response Support

Recommend or initiate actions when appropriate controls and confidence thresholds are met.

Signature vs ML / Behaviour Detection

Signature

"Does this match something we already recognise as malicious?"

KNOWN PATTERN

ML / Behaviour

"Does this activity resemble malicious or unusual behaviour?"

PATTERN / ANOMALY

Possible anomaly

User normally downloads: 20 MB per day.

Today: 480 GB downloaded at 02:00.

Unusual does not automatically mean malicious. It means investigate the context.
๐Ÿค– AI Security Tools Are Still Security Controls They need validation, monitoring and governance
False Positives

Normal behaviour may be classified as malicious.

False Negatives

Malicious behaviour may not be recognised.

Model Drift

Real-world behaviour changes over time and the model may become less representative.

Poor Data

Weak or incomplete data can reduce detection quality.

Adversarial Behaviour

Attackers may deliberately alter behaviour to evade detection.

Explainability

Analysts may need enough information to understand why a high-impact decision was made.

Automation Risk

Incorrect high-confidence decisions can cause operational impact if automatically enforced.

Human Oversight

Important decisions may still require analyst judgement and contextual validation.

AI can improve detection. AI does not eliminate the need to validate detection.
๐Ÿ“‰ Model Drift The environment the model learned may change
Before

Employees normally work: 09:00 - 17:00 from office networks.

After organisational change

Employees work: globally and remotely around the clock.

A behavioural model based entirely on the original pattern may suddenly generate:

large numbers of false positives.

The environment changes. Detection models must be evaluated as the environment changes.

Detection Confidence & Automated Action

Low Confidence โ†’ Record / Enrich
Medium Confidence โ†’ Alert Analyst
High Confidence + Low Operational Risk โ†’ Automated Prevention May Be Appropriate
High Business Impact โ†’ Human / Policy Approval May Be Required
Confidence and consequence both matter when deciding whether detection should automatically become prevention.
The Words People Forget

Operate AND Maintain

The ISC2 objective is not simply:

"know what these technologies are."

It says:

operate and maintain.

Health

Is the control functioning?

Coverage

Is it protecting the systems it should protect?

Configuration

Is the policy appropriate?

Updates

Are engines, signatures, intelligence and software current?

Tuning

Is detection producing useful results?

Logging

Are important events reaching monitoring systems?

Testing

Does the control detect or block what it should?

Review

Does the control still match current threats and business needs?

Operate & Maintain

RUN Control operational
UPDATE Keep current
TUNE Improve signal
TEST Verify effectiveness
REVIEW Still appropriate?
๐Ÿงช Do Not Assume the Control Works Security technology should be validated
Organisation believes

IPS blocks: a known exploit.

Controlled test reveals

Relevant IPS signature: disabled.

Installed โ‰  enabled. Enabled โ‰  configured correctly. Configured โ‰  effective. Test it.

Detection Coverage

Security teams should understand which parts of the environment are actually covered by controls.

Claim

"All endpoints have EDR."

Reality

Coverage: 92%.

Missing:

Legacy Servers Recently Built Systems Some Cloud Workloads
A control cannot protect an asset it does not cover.
Architecture

Sensor Placement Matters

Detection effectiveness depends partly on where monitoring controls are positioned.

Internet Edge

Observe external inbound and outbound traffic.

Internal Segments

Detect lateral movement between zones.

Critical Server Networks

Monitor traffic involving high-value assets.

Cloud Networks

Observe cloud-native traffic and workloads.

Perimeter detection โ‰  internal detection

Once an attacker is inside the network, east-west visibility may become especially important.

๐Ÿ” Encrypted Traffic Creates Visibility Questions Security controls may see metadata but not necessarily application contents
Network IDS

Sees: TLS connection.

Payload: encrypted.

Depending on architecture, detection may rely on:

TLS Inspection Endpoint Telemetry Flow Metadata Application Logs Behaviour Analytics
Encryption protects confidentiality but can affect inspection visibility.
Availability vs Security

Fail Open vs Fail Closed

Fail Open

If the security control fails, traffic or access continues.

Benefit: availability.

Risk: security inspection may be bypassed.

Fail Closed

If the security control fails, traffic or access is denied.

Benefit: security enforcement.

Risk: service disruption.

Fail secure is the security principle. Architecture must still account for availability and safety requirements.
โ™ป๏ธ Security Controls Can Become Single Points of Failure Inline controls need resilience
Architecture

Every customer transaction passes through: one IPS appliance.

Appliance fails.

Depending on design:

Traffic Stops Security Is Bypassed
Critical preventive controls may require redundancy and resilient design.

Detection Controls Need Change Management

Modifying security controls can affect production traffic and detection capability.

Rule Change โ†’ Assess Impact
Approve โ†’ Controlled Implementation
Test โ†’ Expected Behaviour
Unexpected Result โ†’ Rollback
IPS update

New prevention signature incorrectly identifies normal banking application traffic as malicious.

Result: customer transactions blocked.

Security control changes can create business risk too.
Operational Effectiveness

Useful Detection & Prevention Metrics

Coverage

What percentage of required assets are protected?

Control Health

How many sensors or agents are functioning?

Detection Quality

How useful are generated alerts?

False-Positive Rate

How often does the control incorrectly identify benign activity?

Detection Gap

Which known threats or techniques lack coverage?

Update Status

Are signatures, engines and threat intelligence current?

Rule Age

Are old firewall or prevention rules still required?

Control Effectiveness

Do controlled tests demonstrate that intended attacks are detected or blocked?

Practical Scenario

Malicious Email Attachment

Email Arrives โ†’ Email Security Gateway
Known Malicious Hash? โ†’ Blocklist Check
Unknown File โ†’ Sandbox
Suspicious Behaviour โ†’ Attachment Blocked
Endpoint Receives Similar File โ†’ Anti-Malware Detects
Security Telemetry โ†’ SOC Investigation
Multiple controls provide multiple opportunities to stop the attack.
Firewall Scenario

The Forgotten Temporary Rule

An engineer creates a temporary rule:

Internet โ†’ Production Database โ†’ Database Port

It is required for: 30 minutes.

Troubleshooting Ends โ†’ Rule Remains
6 Months Later โ†’ Firewall Review
No Business Need โ†’ Remove Rule
Preventive controls require lifecycle management too.
IDS / IPS Scenario

The Noisy Signature

IDS generates: 40,000 alerts every day.

Analysts discover: 39,800 are legitimate application behaviour.

Detection โ†’ Too Broad
Result โ†’ False Positives
Operational Effect โ†’ Alert Fatigue
Response โ†’ Tune Detection
More alerts โ‰  better detection.
Detection Scenario

The Silent Attack

An attacker exploits a web server.

IDS: does not alert.

The attack is later discovered through endpoint telemetry.

Attack exists + detection says normal = false negative.
Operational lesson

Determine why the detection failed and use the incident to improve coverage.

Deception Scenario

The Fake Domain Administrator Credential

Security places a monitored fake credential in a location that should never be accessed by legitimate users.

Attacker Finds Credential โ†’ Attempts Authentication
Authentication โ†’ High-Priority Alert
SOC โ†’ Investigates Source Host
Nobody legitimate should use the decoy. Use of the decoy therefore creates valuable context.
Third-Party Scenario

The MDR Alert

An external MDR provider identifies suspicious administrator activity at:

02:15.

The provider's contract allows it to:

alert the company

but not:

disable accounts or isolate servers.

MDR โ†’ Detects
MDR โ†’ Escalates
Organisation โ†’ Authorises Response
Know where provider authority ends and organisational responsibility begins.
AI Detection Scenario

Unusual Administrator Behaviour

A behavioural model identifies:

03:00 Login New Country New Device Large Data Download Privilege Change

Each signal individually might be legitimate.

Together they create:

a high-risk behavioural anomaly.

AI and behavioural analytics can help find suspicious combinations of weak signals.
๐ŸŽ“ CISSP Scenarios Recognise the detection or preventive measure being tested
Scenario 1

A control blocks network traffic that is not explicitly authorised.

Which control?

Firewall.

Scenario 2

A network device allows only explicitly required communications.

Which principle?

Default deny / least privilege.

Scenario 3

A control permits TCP 443 but does not understand the malicious HTTP request inside it.

Which additional control may help?

Web Application Firewall.

Scenario 4

Security needs to inspect HTTP parameters for attacks against a web application.

Which control?

WAF.

Scenario 5

A firewall combines application identification, threat intelligence and intrusion prevention.

Which firewall type?

Next-Generation Firewall.

Scenario 6

A firewall controls communications on an individual laptop.

Which type?

Host-based firewall.

Scenario 7

Security controls traffic entering the corporate environment.

Which direction?

Ingress.

Scenario 8

Security blocks a compromised server from contacting an attacker externally.

Which direction is being controlled?

Egress.

Scenario 9

A temporary firewall rule remains years after the project closed.

Which operational weakness?

Poor firewall rule lifecycle management.

Scenario 10

An IDS identifies malicious network traffic and generates an alert.

Which control function?

Detective.

Scenario 11

An IPS detects the same traffic and drops it.

Which functions?

Detective and preventive.

Scenario 12

A security sensor receives a copy of network traffic but does not sit directly in the path.

Which deployment style?

Passive monitoring.

Scenario 13

Traffic must pass directly through a security device that can drop packets.

Which deployment style?

Inline.

Scenario 14

Detection looks for a byte pattern associated with known malware.

Which method?

Signature-based detection.

Scenario 15

Detection identifies a user downloading 500 times their normal data volume.

Which general method?

Anomaly / behaviour detection.

Scenario 16

Normal business activity triggers a malware alert.

Which result?

False positive.

Scenario 17

Real malicious activity occurs but the IDS produces no alert.

Which result?

False negative.

Scenario 18

Thousands of harmless alerts consume analyst time.

What may be required?

Detection tuning.

Scenario 19

A real attack was missed.

What should occur afterwards?

Detection coverage should be reviewed and improved.

Scenario 20

Only approved applications are permitted to execute.

Which concept?

Application allowlisting / whitelisting.

Scenario 21

Known malicious domains are prohibited.

Which concept?

Blocklisting / blacklisting.

Scenario 22

Security wants to control what is permitted rather than continuously identify every possible malicious program.

Which approach?

Allowlisting.

Scenario 23

A new malicious domain has not yet appeared on any denylist.

Can blocklisting alone stop it?

Not necessarily.

Scenario 24

A legitimate software update is blocked because the allowlist was not updated.

Which lesson?

Allowlisting requires operational maintenance.

Scenario 25

An external organisation monitors endpoint alerts around the clock.

Which 7.7 topic?

Third-party provided security services.

Scenario 26

An MDR provider detects an attack but does not have authority to isolate the endpoint.

What must be clear?

Escalation and response responsibilities.

Scenario 27

An organisation outsources security monitoring.

Does it outsource accountability for security risk?

No.

Scenario 28

Unknown executable is run inside an isolated analysis environment.

Which technique?

Sandboxing.

Scenario 29

Malware behaves harmlessly because it detects a virtual analysis environment.

Which technique?

Sandbox evasion.

Scenario 30

A sandbox reports no malicious activity.

Does this prove the file is benign?

No.

Scenario 31

A deliberately attractive fake server is deployed to identify attackers.

Which control?

Honeypot.

Scenario 32

An entire fake network environment is deployed.

Which control?

Honeynet.

Scenario 33

A fake API key generates an alert when attackers attempt to use it.

Which related concept?

Honeytoken.

Scenario 34

A compromised honeypot can reach production servers.

Primary concern?

Insufficient isolation.

Scenario 35

A security product compares a file with known malicious patterns.

Which anti-malware method?

Signature detection.

Scenario 36

Security software observes a process encrypting thousands of files and blocks it.

Which method?

Behaviour-based anti-malware detection.

Scenario 37

Endpoint agent is installed but has not received updates for six months.

Primary concern?

Control maintenance / outdated protection.

Scenario 38

Endpoint protection unexpectedly stops on one production server.

Why investigate?

Attackers may attempt to disable security controls.

Scenario 39

A machine-learning system identifies abnormal user behaviour.

Is unusual behaviour automatically malicious?

No. Context and validation are required.

Scenario 40

Remote work changes normal user behaviour and the AI system begins producing many false alarms.

Possible issue?

Model or behavioural drift.

Scenario 41

AI automatically disables a critical production account based on a low-confidence alert.

Primary concern?

Inappropriate automation without sufficient confidence or guardrails.

Scenario 42

Security wants to know whether all required endpoints actually have active EDR.

Which metric?

Control coverage and health.

Scenario 43

An organisation has excellent internet-edge IDS visibility but none between internal network segments.

Which gap?

Internal / east-west detection coverage.

Scenario 44

Network IDS sees encrypted TLS sessions but cannot inspect the application payload.

Which issue?

Encrypted-traffic visibility.

Scenario 45

An IPS fails and all network traffic stops.

Which behaviour?

Fail closed.

Scenario 46

The same IPS fails and traffic bypasses security inspection.

Which behaviour?

Fail open.

Scenario 47

One inline firewall failure can stop every customer transaction.

Which architecture concern?

Single point of failure / resilience.

Scenario 48

A new IPS signature is deployed and starts blocking legitimate traffic.

Which operational controls matter?

Testing, tuning, change management and rollback.

Scenario 49

Security purchased an expensive detection product but never checks whether it identifies the attacks it was intended to detect.

Primary weakness?

Control effectiveness has not been validated.

Scenario 50

Management asks for the central principle of CISSP 7.7.

Best answer?

Operate layered preventive and detective controls, keep them healthy and current, tune them to the environment and verify that they actually provide the intended protection.

CISSP Exam Perspective

Recognise the Clue Words

Permit / Deny Network Traffic

Boundary control.

Firewall

HTTP Attack

Application traffic.

WAF

Application-Aware Firewall

Advanced inspection.

NGFW

Traffic Coming In

Direction.

Ingress

Traffic Going Out

Direction.

Egress

Detect Only

Alert.

IDS

Detect + Block

Prevention.

IPS

Traffic Copy

Observe.

Passive IDS

Traffic Passes Through

Enforce.

Inline IPS

Known Attack Pattern

Pattern match.

Signature

Unusual Behaviour

Deviation.

Anomaly Detection

Alarm ยท No Attack

Wrong alarm.

False Positive

Attack ยท No Alarm

Miss.

False Negative

Too Many Alerts

Improve quality.

Tuning

Only Approved Software

Known good.

Allowlisting

Known Malicious Domain

Known bad.

Blocklisting

MDR / MSSP

External security capability.

Third-Party Service

Run Suspicious File Safely

Isolation.

Sandbox

Malware Knows It Is Analysed

Hide behaviour.

Sandbox Evasion

Fake Server

Deception.

Honeypot

Fake Network

Deception environment.

Honeynet

Fake Credential

Tripwire.

Honeytoken

Known Malware Pattern

Endpoint scan.

Anti-Malware Signature

Ransomware-Like Behaviour

Behaviour.

Anti-Malware / EDR

Security Agent Stopped

Control tampering?

Investigate

ML Behaviour Changed

Environment changed.

Model Drift

AI Says Suspicious

Not proof.

Validate Context

Is Control Running?

Operational state.

Control Health

Are All Assets Protected?

Reach.

Coverage

Does It Actually Detect?

Assurance.

Effectiveness Testing

Failure Permits Traffic

Availability favoured.

Fail Open

Failure Blocks Traffic

Security enforcement.

Fail Closed
โš ๏ธ Common CISSP Mistakes Know what the control actually does
Preventive โ‰  Detective

Prevention attempts to stop activity. Detection identifies activity.

One Product โ‰  One Control Function

An IPS can detect and prevent.

Firewall โ‰  Complete Security

Permitted traffic can still contain attacks.

Network Firewall โ‰  WAF

They inspect and protect different aspects of communication.

NGFW โ‰  Automatically Secure

Configuration still matters.

Ingress Filtering โ‰  Egress Filtering

One controls inbound traffic, the other outbound.

Firewall Rule Created โ‰  Firewall Rule Needed Forever

Rules require review and retirement.

IDS โ‰  IPS

IDS primarily detects. IPS can attempt to prevent.

Passive IDS โ‰  Inline IPS

Passive sensors observe; inline controls can directly enforce traffic decisions.

Signature Detection โ‰  Unknown-Threat Detection

Signatures are strongest when malicious patterns are already known.

Anomaly โ‰  Malicious

Legitimate behaviour can also be unusual.

More Alerts โ‰  Better Security

Detection needs useful signal rather than unlimited noise.

False Positive โ‰  False Negative

False positive = harmless activity alerted.

False negative = attack missed.

Allowlist โ‰  Blocklist

Allowlisting defines what may operate. Blocklisting defines what may not.

Blocklist โ‰  Protection From Everything New

Unknown malicious entities may not yet appear on the list.

Allowlisting โ‰  Maintenance Free

Legitimate software changes must be accommodated.

MDR Provider โ‰  Organisation Has No Response Duties

Provider and customer responsibilities must be defined.

Outsource Detection โ‰  Outsource Risk

Accountability remains with the organisation.

Sandbox โ‰  Proof of Safety

Malware can alter behaviour or evade analysis.

Sandbox โ‰  Impossible to Escape

Isolation technology can also have weaknesses.

Honeypot โ‰  Production Server

Its primary purpose is deception and observation.

Honeypot โ‰  Safe Without Isolation

A compromised decoy should not provide access to real assets.

Antivirus Installed โ‰  Antivirus Effective

Health, updates, configuration and coverage matter.

Anti-Malware โ‰  Only Signatures

Modern protection may include heuristics, behaviour and reputation.

Security Agent Disabled โ‰  Ordinary IT Problem

Attackers may intentionally disable security controls.

AI Prediction โ‰  Fact

Model output requires appropriate interpretation.

AI โ‰  No False Positives

Machine-learning tools still make classification errors.

AI โ‰  Static Forever

Environment and model behaviour should be monitored for drift.

Automation โ‰  Automatic Authority

High-impact preventive actions may need appropriate guardrails.

Encrypted Traffic โ‰  Invisible Attack

Alternative telemetry and inspection points may still provide useful detection.

Perimeter Detection โ‰  Complete Detection Coverage

Internal and cloud environments may require additional visibility.

Fail Closed โ‰  Always Operationally Simple

Blocking traffic during control failure may affect critical service availability.

Fail Open โ‰  Secure Failure

Traffic may continue without required inspection.

Security Appliance โ‰  Cannot Be Single Point of Failure

Inline controls may require resilience and redundancy.

Installed โ‰  Effective

Detection and prevention should be validated through appropriate testing.

Quick Reference

If you see...Think...
Control network communicationFirewall
Protect HTTP application trafficWAF
Application-aware firewall + threat inspectionNGFW
Traffic enteringIngress
Traffic leavingEgress
Detect intrusionIDS
Detect and stop intrusionIPS
Known malicious patternSignature
Unusual behaviourAnomaly Detection
Benign activity generates alertFalse Positive
Attack generates no alertFalse Negative
Too much detection noiseTuning
Only approved entities allowedAllowlisting
Known malicious entities deniedBlocklisting
External detection providerMDR / MSSP
Restricted execution environmentSandbox
Malware hides from analysisSandbox Evasion
Decoy serverHoneypot
Decoy networkHoneynet
Decoy credential or recordHoneytoken
Detect malicious softwareAnti-Malware
Endpoint telemetry + responseEDR
Security agent unexpectedly stoppedPossible Defence Evasion
ML identifies unusual patternAI / Behaviour Detection
Normal behaviour changes over timeModel Drift
Does control cover all assets?Coverage
Is sensor functioning?Control Health
Does control detect the attack?Effectiveness Testing
Failure permits trafficFail Open
Failure denies trafficFail Closed

Firewall Memory Aid

DEFINE Policy
FILTER Traffic
LOG Activity
REVIEW Rules
REMOVE What is no longer required

IDS / IPS Memory Aid

IDS Detect + Alert
IPS Detect + Attempt to Prevent
SIGNATURE Known pattern
ANOMALY Unexpected behaviour
TUNE Useful signal

Allow / Block Memory Aid

ALLOWLIST What IS permitted?
BLOCKLIST What is NOT permitted?

Allowlist = Known Good ยท Blocklist = Known Bad

Isolation & Deception Memory Aid

SANDBOX Run suspicious code somewhere restricted
HONEYPOT Fake system
HONEYNET Fake network
HONEYTOKEN Fake information / credential

7.7 Master Memory Aid

FILTER Firewall
DETECT / BLOCK IDS / IPS
ALLOW / DENY Lists
OUTSOURCE Third-party services
ISOLATE Sandbox
DECEIVE Honeypots
SCAN Anti-malware
LEARN ML / AI
MAINTAIN Everything

Prevent โ†’ Detect โ†’ Tune โ†’ Test โ†’ Improve

The Security Operations Questions

PROTECT? Which threat is this control addressing?
PREVENT? Can the control stop it?
DETECT? Can the control see it?
COVERAGE? Which assets are actually protected?
HEALTH? Is the control functioning?
CURRENT? Are rules, signatures and intelligence updated?
NOISY? Are false positives overwhelming analysts?
BLIND? Which attacks could still pass undetected?
TUNED? Does detection reflect the real environment?
TESTED? Do we know that it works?
RESILIENT? What happens if the control fails?
OWNER? Who maintains it?

Key Takeaways

CISSP 7.7 focuses on operating and maintaining detection and preventative security measures.

The current CISSP outline explicitly includes firewalls, IDS/IPS, whitelisting/blacklisting, third-party security services, sandboxing, honeypots/honeynets, anti-malware and machine-learning/AI-based tools.

Prevention and detection are different security-control functions.

Preventive controls attempt to stop unwanted activity from succeeding.

Detective controls identify potentially malicious activity so it can be investigated or acted upon.

Some controls perform both functions.

Prevention = stop it. Detection = find it.

Defence in depth means relying on several complementary controls rather than expecting one product to stop every attack.

A firewall controls network communication according to security policy.

Firewall decisions may consider addresses, protocols, ports, connection state, applications, users and other contextual information depending on the technology.

Network firewalls and Web Application Firewalls operate at different levels.

A network firewall can permit HTTPS while a WAF separately identifies a malicious HTTP request carried inside that permitted service.

Network firewall = should this network communication occur? WAF = is this web request appropriate?

Next-generation firewalls can combine traditional firewall capabilities with deeper application and threat inspection.

Advanced technology does not compensate for poor configuration.

Firewall policy should follow business requirements and least privilege.

Default-deny approaches allow explicitly required communications and deny other traffic.

Ingress controls traffic entering a network or security zone.

Egress controls traffic leaving it.

Egress filtering can help prevent or identify compromised systems communicating with attacker infrastructure.

Firewall rules require lifecycle management.

Rules should be requested, justified, approved, implemented, tested, monitored, reviewed and removed when no longer required.

Temporary rules are particularly dangerous when temporary quietly becomes permanent.

Intrusion Detection Systems identify potentially malicious activity.

Intrusion Prevention Systems can detect malicious activity and also attempt to stop it.

IDS = detect and alert. IPS = detect and attempt to prevent.

Passive sensors can observe copies of network traffic.

Inline controls sit in the enforcement path and can directly influence traffic.

Network-based detection focuses on communications.

Host-based detection provides visibility into activity occurring on individual systems.

Signature-based detection identifies known malicious patterns.

Anomaly or behaviour-based detection identifies activity that differs from expected patterns.

Signature = have I seen this malicious pattern? Anomaly = does this behaviour look unusual?

Unusual does not automatically mean malicious.

A false positive occurs when harmless activity is incorrectly identified as malicious.

A false negative occurs when malicious activity is incorrectly treated as benign or remains undetected.

False positive = alarm without attack. False negative = attack without alarm.

Excessive false positives create alert fatigue and consume analyst resources.

Detection tuning attempts to improve useful signal while preserving important coverage.

Detection should evolve as applications, users, networks and threats change.

The CISSP outline still uses the terms whitelisting and blacklisting.

Modern documentation also commonly uses allowlisting and blocklisting or denylisting.

Allowlisting defines what is permitted.

Blocklisting defines what is prohibited.

Allowlist = known or approved good. Blocklist = known bad.

Application allowlisting can prevent execution of software that is not explicitly authorised.

This can be very powerful where the authorised software set is reasonably controlled.

It also requires good change management because legitimate applications and versions change.

Blocklists are useful for known malicious domains, addresses, hashes, applications and other indicators.

However, a blocklist cannot automatically recognise malicious infrastructure that has never been identified before.

Third-party security providers can deliver detection and preventive capabilities.

Examples include managed security monitoring, managed detection and response, DDoS protection, cloud WAF, email filtering and DNS security.

Provider responsibilities should be clearly defined.

Organisations should understand what is monitored, when monitoring occurs, how alerts are escalated, what actions the provider may perform and what information remains available to the customer.

Outsourcing the security service does not outsource accountability for organisational risk.

Sandboxing provides a restricted environment for executing untrusted or suspicious code.

Security systems can observe file, process, network and persistence behaviour before deciding whether the content should be permitted.

Sandbox results are not absolute proof that software is safe.

Malware can attempt to identify analysis environments and hide its malicious behaviour.

This is commonly known as sandbox evasion.

The sandbox itself must also be securely isolated because vulnerabilities in the isolation mechanism can create sandbox-escape risk.

Honeypots are deceptive systems or resources designed to attract suspicious activity.

Honeynets extend the deception concept across multiple systems or an apparent network.

Honeytokens apply similar thinking to deceptive information such as fake credentials, keys or records.

Honeypot = fake system. Honeynet = fake network. Honeytoken = fake information.

Because legitimate users should have little reason to interact with properly designed deception resources, such activity can generate useful security signals.

Honeypots must be appropriately isolated so a compromised decoy cannot become an attack platform against production systems.

Anti-malware technology can use signatures, heuristics, behavioural analysis and reputation information to identify malicious software.

Prevention capabilities may block or quarantine malicious programs before they execute successfully.

Modern endpoint protection and EDR capabilities can extend beyond traditional antivirus by providing behaviour telemetry, investigation, threat hunting and response functions.

Anti-malware protection should be maintained and monitored.

Security teams should know whether the agent is installed, running, updated, correctly configured and communicating with its management service.

Installed โ‰  healthy. Healthy โ‰  current. Current โ‰  effective.

Attackers can attempt to disable security controls, including endpoint agents, logs and firewall policies.

Unexpected loss of a security control can therefore itself be valuable security telemetry.

Machine-learning and AI-based tools can analyse large quantities of security information and identify patterns, anomalies and correlations.

Possible uses include malware classification, behaviour analytics, alert prioritisation, network anomaly detection and analyst assistance.

AI-based detection still produces false positives and false negatives.

Its output should therefore be interpreted according to context and risk.

Behavioural models can lose effectiveness when normal organisational behaviour changes.

This creates the need to consider model and behavioural drift.

Attackers may also deliberately modify their behaviour to evade detection.

Automated preventive action should consider both:

detection confidence and consequence of being wrong.

A low-confidence automated decision that shuts down a critical service can itself cause substantial business harm.

"Operate and maintain" is an important part of the 7.7 objective.

Controls should be monitored for health, coverage, configuration, updates, tuning and effectiveness.

Security teams should understand which assets are actually protected.

A control cannot protect an asset it does not cover.

Sensor placement influences visibility.

Internet-edge monitoring alone may not identify lateral movement between internal systems.

Encrypted traffic also changes what network controls can inspect.

Endpoint telemetry, application logs, flow information and appropriately designed inspection points can provide complementary visibility.

Inline security controls can create availability dependencies.

Fail-open behaviour prioritises continued communication when the control fails but may allow traffic to bypass inspection.

Fail-closed behaviour denies communication when the control fails but can affect availability.

Critical inline controls may therefore require resilient architectures.

Changes to firewalls, IPS rules and other preventive technologies should be controlled and tested.

An incorrectly configured security control can block legitimate business activity just as effectively as it blocks an attacker.

Security measures should therefore be tested rather than merely assumed to work.

Installed โ‰  enabled. Enabled โ‰  configured correctly. Configured correctly โ‰  proven effective.

Detection and preventive controls work best as layers.

A firewall may miss an application attack that a WAF catches.

A WAF may miss malware that endpoint security catches.

Endpoint security may miss behaviour that identity analytics detects.

The central CISSP principle is: deploy layered preventive and detective measures, understand what each control can and cannot see, keep the controls healthy and current, tune them to the environment and verify regularly that they provide the protection you expect.

๐Ÿ“š Sources & Further Reading Detection, prevention and security-control references