CompTIA DataSys+ (DS0-001)Data and Database SecurityHard
A security operations center (SOC) analyst observes a pattern of unauthorized attempts to access a critical database, originating from a known malicious IP address. The attempts involve various SQL commands designed to probe for vulnerabilities. The analyst needs a solution that can actively block these malicious connection attempts in real-time before they reach the database server. Which security tool is BEST suited for this purpose?
- AIntrusion Prevention System (IPS)
- BVulnerability scanner
- CSecurity Information and Event Management (SIEM) system
- DData Loss Prevention (DLP) solution
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) actively monitors network traffic for malicious activity and can automatically block or drop suspicious packets in real-time, preventing attacks from reaching the target system, such as a database server.
Why the other options are wrong
- B. A vulnerability scanner identifies weaknesses but does not actively block ongoing attacks.
- C. A SIEM system collects and analyzes logs but primarily for detection and alerting, not active, real-time blocking.
- D. A DLP solution focuses on preventing sensitive data from leaving the organization, not blocking incoming attacks.
Intrusion Prevention System (IPS)
A network security device or software application that monitors network or system activities for malicious policy violations and can react in real-time to block or prevent those activities.
- Actively blocks or drops malicious traffic.
- Often deployed inline to inspect all traffic.
- Uses signature-based, anomaly-based, or policy-based detection methods.
Memory trick: IPS prevents, others just watch or find.