CompTIA Cloud+ (CV0-004)SecurityHard
A financial institution is deploying a critical database in a public cloud. Due to stringent regulatory requirements, all network traffic to and from this database must be continuously monitored for malicious activity, and any detected threats must be automatically blocked in real-time. Which cloud security service should be implemented?
- ANetwork Security Group (NSG)
- BIntrusion Prevention System (IPS)
- CVirtual Private Network (VPN)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: B. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) is specifically designed to not only detect (like an IDS) but also actively block or prevent malicious network traffic in real-time. This aligns with the requirement for continuous monitoring and automatic blocking of detected threats for a critical database under stringent regulatory requirements.
Why the other options are wrong
- A. NSGs provide basic stateful firewalling based on IP addresses and ports, but do not offer advanced threat detection and prevention capabilities.
- C. A VPN provides encrypted communication tunnels for secure data transmission but does not monitor for or prevent malicious activity within the tunnel.
- D. An IDS detects malicious activity and generates alerts but does not automatically block threats, which is a key requirement.
Intrusion Prevention System (IPS)
An IPS is a network security device that monitors network and/or system activities for malicious policy violations and can automatically react to block or prevent detected threats in real-time.
- Combines detection (IDS) with active prevention capabilities.
- Analyzes traffic for signatures and anomalies.
- Can drop malicious packets, reset connections, or block source IPs.
Memory trick: IPS prevents, IDS just informs.