CompTIA Network+ (N10-009)Networking ConceptsMedium

A security team wants a network appliance that actively blocks malicious traffic in real time by sitting inline with the traffic flow, rather than only alerting administrators after detecting an attack. Which device should be deployed?

  1. AIntrusion detection system (IDS)
  2. BProxy server
  3. CIntrusion prevention system (IPS)
  4. DLoad balancer
Show answer & explanation

Correct answer: C. Intrusion prevention system (IPS)

An IPS is deployed inline and can actively block or drop malicious traffic in real time, whereas an IDS only monitors and alerts without taking direct action.

Why the other options are wrong

  • A. An IDS passively monitors traffic and generates alerts but does not block traffic.
  • B. A proxy server manages client requests but does not specialize in real-time threat blocking.
  • D. A load balancer distributes traffic across servers and does not perform security filtering.

IPS vs IDS

An IPS is an inline device that actively blocks malicious traffic, while an IDS is a passive device that only detects and alerts on suspicious activity.

  • IPS = inline, active blocking
  • IDS = out-of-band, passive alerting
  • Both use signature/anomaly detection

Memory trick: IDS = 'I Detect and Signal', IPS = 'I Prevent and Stop'.

More Networking Concepts questions