CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A security analyst observes a pattern of unauthorized attempts to access a database by repeatedly trying common usernames and passwords from a list. These attempts are originating from various IP addresses globally, but always targeting the same database and specific user accounts. Which security solution is MOST effective at detecting and automatically blocking such brute-force attacks in real-time?
- AIntrusion Prevention System (IPS)
- BData Loss Prevention (DLP)
- CSecurity Information and Event Management (SIEM)
- DFirewall with port blocking
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) is designed to monitor network traffic and system activities for malicious patterns, such as brute-force login attempts. Upon detection, it can automatically block the malicious traffic or user, providing real-time protection against such attacks.
Why the other options are wrong
- B. DLP focuses on preventing sensitive data from leaving the organization, not on blocking intrusion attempts.
- C. SIEM collects and analyzes logs for security events but typically relies on an analyst to react, not automatically block in real-time.
- D. A firewall with port blocking controls network access at a basic level but isn't designed to detect and block sophisticated brute-force attack patterns.
Intrusion Prevention System (IPS)
A network security device that monitors network traffic for malicious activity or policy violations and can automatically prevent or block detected threats.
- Detects and blocks known attack signatures and anomalies.
- Operates in real-time to prevent intrusions.
- Can be network-based (NIPS) or host-based (HIPS).
Memory trick: To stop threats, you need both eyes and a shield.