Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security operations center (SOC) analyst is investigating an alert from an Intrusion Prevention System (IPS) indicating a potential buffer overflow attack. The IPS has successfully blocked the traffic. The analyst needs to determine if the attack attempt was indeed a buffer overflow and identify its source and target. What type of security monitoring concept is the IPS primarily demonstrating in this scenario?

  1. ANetwork Intrusion Detection/Prevention
  2. BLog Management
  3. CEndpoint Detection and Response (EDR)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: A. Network Intrusion Detection/Prevention

An IPS (Intrusion Prevention System) actively monitors network traffic for malicious activity and can automatically block or prevent detected threats, such as a buffer overflow attack. This falls under the category of network intrusion detection and prevention, which focuses on analyzing network traffic for attacks.

Why the other options are wrong

  • B. Log management is about collecting and storing logs, not active network traffic analysis and blocking.
  • C. EDR focuses on endpoints (servers, workstations), not primarily on network traffic analysis and blocking.
  • D. SIEM aggregates and correlates security events from various sources, but the IPS itself is the network-level detection/prevention component.

Network Intrusion Prevention System (IPS)

A network security appliance that monitors network traffic for malicious activity, logs information about it, attempts to block it, and reports it.

  • Active prevention of network attacks.
  • Operates in-line with network traffic.
  • Can block known attack signatures and anomalies.

Memory trick: IDS/IPS are the network guards, watching and blocking bad traffic.

More Security Concepts questions