ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A network security team is deploying an Intrusion Prevention System (IPS) to protect critical internal servers. The team wants the IPS to actively block malicious traffic before it reaches the servers, rather than just alerting. To achieve this immediate preventive action, in which deployment mode should the IPS be configured?
- AOut-of-band mode
- BInline mode
- CPromiscuous mode
- DPassive mode
Show answer & explanationAnswer & explanation
Correct answer: B. Inline mode
Inline mode (also known as in-band mode) places the IPS directly in the network path, allowing it to inspect all traffic and actively block or drop malicious packets before they reach their destination, fulfilling the requirement for immediate preventive action.
Why the other options are wrong
- A. Out-of-band mode is another term for passive mode, where the IPS receives a copy of traffic and cannot block it.
- C. Promiscuous mode is a synonym for passive or out-of-band, where the IPS only monitors traffic.
- D. Passive mode (or promiscuous/out-of-band) only monitors traffic and generates alerts, without actively blocking.
IPS Inline Mode
A deployment configuration where an Intrusion Prevention System (IPS) is placed directly in the network traffic path, allowing it to actively block or drop malicious traffic.
- IPS acts as a gatekeeper for traffic.
- Provides real-time prevention and enforcement.
- Introduces a single point of failure if not redundant.
Memory trick: Inline blocks, Passive watches.