CompTIA Security+ (SY0-701)Security OperationsMedium

A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. This device automatically updates its block lists based on feeds from various threat intelligence sources. Which security control is being implemented?

  1. ASecurity Orchestration, Automation, and Response (SOAR)
  2. BEndpoint Detection and Response (EDR)
  3. CFirewall with integrated threat intelligence
  4. DNext-Generation Antivirus (NGAV)
Show answer & explanation

Correct answer: C. Firewall with integrated threat intelligence

A firewall, especially a next-generation firewall (NGFW), is a network device that filters traffic. When it integrates with threat intelligence feeds to automatically block known malicious IPs and domains, it acts as a proactive security control at the network perimeter.

Why the other options are wrong

  • A. SOAR platforms orchestrate and automate security workflows, but they are not the network device performing the blocking.
  • B. EDR provides visibility and response capabilities on endpoints, not network-level blocking.
  • D. NGAV protects endpoints, not network traffic at a perimeter device.

Firewall with Integrated Threat Intelligence

A network security device that filters incoming and outgoing network traffic, enhanced by automatically updated threat intelligence feeds to block known malicious sources.

  • Operates at the network perimeter or internal segments.
  • Uses threat intelligence to proactively block IP addresses, domains, and URLs.
  • Often a feature of Next-Generation Firewalls (NGFWs).

Memory trick: A firewall is like a 'Fortress Wall' that uses intel.

More Security Operations questions