ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
A security analyst is investigating a series of unauthorized access attempts originating from a compromised internal host. The attacker appears to be scanning for open ports on other internal systems and attempting to establish connections. Which network security device is primarily responsible for monitoring and analyzing network traffic for malicious activity and alerting administrators?
- ALoad Balancer
- BIntrusion Detection System (IDS)
- CRouter
- DFirewall
Show answer & explanationAnswer & explanation
Correct answer: B. Intrusion Detection System (IDS)
An Intrusion Detection System (IDS) is specifically designed to monitor network or system activities for malicious activity or policy violations and to generate alerts. While a firewall filters traffic, an IDS focuses on detection and alerting.
Why the other options are wrong
- A. A load balancer distributes incoming network traffic across multiple servers to optimize resource utilization and maximize throughput.
- C. A router forwards packets between different networks based on IP addresses and routing tables.
- D. A firewall primarily enforces access control policies by filtering traffic, not detecting malicious activity within permitted flows.
Intrusion Detection System (IDS)
A security device that monitors network or system activities for malicious activity or policy violations and produces reports or alerts.
- Monitors traffic for signatures or anomalies.
- Primarily a detection and alerting tool.
- Does not actively block traffic (unlike IPS).
Memory trick: IDS spots danger, IPS stops it cold.