CompTIA Security+ (SY0-701)Security OperationsMedium
A network security appliance is deployed inline between the internet and the internal network. It is configured so that when it detects a known exploit signature in a packet stream, it immediately drops the malicious packets in real time before they reach the destination host. Which technology is being described?
- AIntrusion prevention system (IPS)
- BIntrusion detection system (IDS)
- CHoneypot
- DSecurity information and event management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion prevention system (IPS)
An IPS is deployed inline and actively blocks or drops malicious traffic in real time based on signatures or anomaly detection. An IDS, by contrast, is typically deployed out-of-band (passive) and only alerts without blocking. A SIEM aggregates and correlates log data rather than blocking packets, and a honeypot is a decoy system used to attract and study attackers.
Why the other options are wrong
- B. IDS only alerts on detected threats; it does not block traffic inline.
- C. A honeypot lures attackers into a decoy system rather than blocking traffic.
- D. SIEM centralizes and correlates logs but doesn't drop packets itself.
Intrusion Prevention System (IPS)
An inline network security device that detects and actively blocks malicious traffic in real time, unlike a passive IDS that only alerts.
- Deployed inline (in the traffic path)
- Can drop packets or reset connections
- Uses signature and/or anomaly-based detection
Memory trick: IPS is a security guard who physically stops the intruder; IDS just shouts an alarm.