ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A network security team is deploying an Intrusion Prevention System (IPS) to protect critical servers. The team wants the IPS to actively block malicious traffic before it reaches the servers, without relying on out-of-band communication or manual intervention for blocking. Which deployment mode should the IPS be configured for?
- APassive Mode
- BSPAN Mode
- CPromiscuous Mode
- DInline Mode
Show answer & explanationAnswer & explanation
Correct answer: D. Inline Mode
In Inline Mode, the IPS is placed directly in the network path, acting as a gatekeeper. All traffic must pass through it, allowing the IPS to actively inspect and block malicious packets in real-time before they reach their destination. Passive and SPAN modes are for detection only.
Why the other options are wrong
- A. Passive Mode (or monitoring mode) only detects and alerts, it does not actively block traffic.
- B. SPAN (Switched Port Analyzer) Mode involves mirroring traffic to the IPS for detection, but the IPS is not in the direct traffic path and cannot block inline.
- C. Promiscuous Mode is a network interface card (NIC) setting to capture all traffic on a segment, not an IPS deployment mode for active blocking.
IPS Inline Mode
A deployment configuration where an Intrusion Prevention System (IPS) is placed directly in the network path, allowing it to actively inspect and block malicious traffic in real-time.
- Acts as a gatekeeper for network traffic.
- Enables active blocking and prevention of threats.
- Can introduce a single point of failure or latency if not properly designed.
Memory trick: Inline IPS is like a 'Traffic Cop' stopping bad cars directly on the road.