地域医療機関のネットワークセキュリティアナリストであるリリーは、予定されている外部脆弱性評価に備えて防御策を準備していた。内部シミュレーション訓練中に、スキャナーが重要システム全体で開いているポートやサービスバナーを正常に検出していることに気づいた。こうした偵察活動への脆弱性を軽減する任務を負ったリリーは、正当なトラフィックを妨げることなく、ポートスキャン活動を具体的に阻止する対策を講じるよう指示された。
リリーは以下のどの行動をとるべきでしょうか?
正解:C
C: Configuring firewall and IDS rules to detect and block probes is the most direct and CEH-aligned countermeasure for hindering port scanning while preserving legitimate traffic. Port scans typically generate recognizable patterns such as many connection attempts across multiple ports in a short time window, repeated SYN packets, abnormal TCP flag combinations, or sequential targeting of hosts and ports. An IDS or IPS can detect these behaviors using thresholds and signatures and then alert or actively block the scanning source through shunning, dynamic ACL updates, or automated firewall integration. This approach focuses on stopping the reconnaissance activity itself, rather than only addressing the symptoms after exposure has already occurred.Option B is partially valid because blocking unwanted ports at the firewall reduces the attack surface, but it is primarily hardening and exposure reduction. It does not necessarily hinder scanning behavior, and overly broad filtering can unintentionally block legitimate services if not carefully scoped. Option A improves security by removing unnecessary services and patching, but scanning can still occur and banners may still be collected from required services. Option D is not appropriate because blocking ICMP type 3 unreachable messages can interfere with normal network operations, troubleshooting, and path MTU discovery, and it does not reliably stop modern scanning techniques that use TCP-based probing.
Therefore, the best action specifically aimed at disrupting port scanning activity with minimal impact on legitimate traffic is tuning firewall and IDS controls to detect and block scan probes.