Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security analyst is investigating an alert from an Intrusion Prevention System (IPS) that blocked suspicious network traffic. The alert indicates that the traffic contained a known exploit signature targeting a specific vulnerability in a web server application. The IPS successfully dropped the malicious packets and prevented the attack from reaching the server. Which type of network security control did the IPS primarily utilize in this scenario?

  1. ANetwork Intrusion Prevention System (NIPS)
  2. BNetwork Intrusion Detection System (NIDS)
  3. CNetwork Access Control (NAC)
  4. DFirewall
Show answer & explanation

Correct answer: A. Network Intrusion Prevention System (NIPS)

A Network Intrusion Prevention System (NIPS) actively monitors network traffic for malicious activity and, upon detection, takes automated actions to prevent the attack, such as blocking or dropping the malicious packets. The scenario explicitly states the IPS 'blocked suspicious network traffic' and 'successfully dropped the malicious packets'.

Why the other options are wrong

  • B. NIDS detects intrusions and alerts, but does not actively prevent them by blocking traffic.
  • C. NAC controls devices allowed on the network, not active threat prevention.
  • D. A firewall filters traffic based on rules (ports, IPs), but an IPS inspects packet content for specific attack signatures.

Network Intrusion Prevention System (NIPS)

A network security device that actively monitors network traffic for malicious activity or policy violations and automatically takes action to block, drop, or prevent such traffic in real-time. It sits inline with network traffic.

  • Actively blocks/drops malicious traffic.
  • Sits inline with network traffic.
  • Prevents attacks in real-time.
  • Can use signature, anomaly, or policy-based detection.

Memory trick: NIPS is the bouncer that actually stops the trouble.

More Security Concepts questions