Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsHard
A technician is configuring a new web server that will host public-facing company information. To enhance security, all traffic to and from this server will be inspected for malicious content and potential intrusions. Which network security technology is primarily responsible for deep packet inspection and signature-based threat detection?
- AIntrusion Prevention System (IPS)
- BFirewall
- CProxy Server
- DLoad Balancer
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion Prevention System (IPS)
While a firewall filters traffic, an Intrusion Prevention System (IPS) goes beyond basic filtering by performing deep packet inspection to analyze the content of traffic for known attack signatures and anomalies, and can actively block malicious traffic, fulfilling the requirement for inspection and intrusion detection.
Why the other options are wrong
- B. A firewall filters traffic based on rules (ports, IPs) but typically doesn't perform deep content inspection for malicious payloads.
- C. A proxy server acts as an intermediary for requests from clients seeking resources from other servers, primarily for caching, filtering, or anonymity, not deep threat detection.
- D. A load balancer distributes network traffic across multiple servers to ensure high availability and responsiveness, not for security inspection.
Intrusion Prevention System (IPS)
A network security device that monitors network traffic for malicious activity and can automatically take action to prevent or block identified threats.
- Performs deep packet inspection
- Uses signature-based and anomaly-based detection
- Actively blocks malicious traffic
- Often deployed in-line with network traffic
Memory trick: IPS 'I'nspects 'P'ackets 'S'ecretly and Stops threats.