ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

A network security team is deploying an Intrusion Prevention System (IPS) to protect critical servers in their data center. The team wants the IPS to actively block malicious traffic in real-time before it reaches the servers, without significantly impacting network latency. Which deployment mode for the IPS would BEST achieve this objective?

  1. AOut-of-Band Mode
  2. BSPAN Port Mode
  3. CPromiscuous Mode
  4. DInline Mode
Show answer & explanation

Correct answer: D. Inline Mode

Inline mode deployment places the IPS directly in the network path, acting as a gatekeeper. All traffic must pass through the IPS, allowing it to inspect, detect, and actively block or drop malicious traffic in real-time before it can reach the target servers. This is crucial for prevention.

Why the other options are wrong

  • A. Out-of-band mode (or passive mode) means the IPS receives a copy of traffic and can only react to threats, not prevent them in real-time.
  • B. SPAN (Switched Port Analyzer) port mode is a form of out-of-band deployment, used for passive monitoring, not active prevention.
  • C. Promiscuous mode is typically for NIDS, where it passively monitors traffic, not actively blocks.

Intrusion Prevention System (IPS) Inline Mode

A deployment method for an IPS where the device is placed directly in the network's traffic path. This allows the IPS to actively inspect all passing traffic and take immediate action, such as blocking or dropping malicious packets, before they reach their intended target.

  • Acts as a gatekeeper, inspecting all traffic.
  • Enables real-time prevention and active blocking of threats.
  • Can introduce a single point of failure if not properly designed with bypass mechanisms.
  • Requires careful tuning to minimize false positives and latency.

Memory trick: Inline IPS Injects Instant Protection.

More Communication and Network Security questions