Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security operations center (SOC) analyst is investigating an alert from an Intrusion Prevention System (IPS) indicating a potential buffer overflow attack. The IPS has successfully blocked the traffic. The analyst needs to determine if the attack attempt was indeed a buffer overflow and identify its source and target. What type of security monitoring concept is the IPS primarily demonstrating in this scenario?
- ANetwork Intrusion Detection/Prevention
- BLog Management
- CEndpoint Detection and Response (EDR)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Intrusion Detection/Prevention
An IPS (Intrusion Prevention System) actively monitors network traffic for malicious activity and can automatically block or prevent detected threats, such as a buffer overflow attack. This falls under the category of network intrusion detection and prevention, which focuses on analyzing network traffic for attacks.
Why the other options are wrong
- B. Log management is about collecting and storing logs, not active network traffic analysis and blocking.
- C. EDR focuses on endpoints (servers, workstations), not primarily on network traffic analysis and blocking.
- D. SIEM aggregates and correlates security events from various sources, but the IPS itself is the network-level detection/prevention component.
Network Intrusion Prevention System (IPS)
A network security appliance that monitors network traffic for malicious activity, logs information about it, attempts to block it, and reports it.
- Active prevention of network attacks.
- Operates in-line with network traffic.
- Can block known attack signatures and anomalies.
Memory trick: IDS/IPS are the network guards, watching and blocking bad traffic.