ISC2 Certified in Cybersecurity (CC)Network SecurityMedium

A large organization with multiple branch offices needs a solution to monitor network traffic for suspicious activity and automatically block known attack patterns in real-time. Which network security device is best suited for both detecting and preventing such malicious activities?

  1. AContent Filter
  2. BIntrusion Prevention System (IPS)
  3. CNetwork Access Control (NAC)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: B. Intrusion Prevention System (IPS)

An IPS actively monitors network traffic for malicious activity and can take automated actions, such as blocking traffic, to prevent attacks in real-time.

Why the other options are wrong

  • A. A content filter blocks access to specific websites or content types, not general attack patterns.
  • C. NAC controls which devices can connect to the network but doesn't actively detect and block ongoing attacks.
  • D. An IDS detects suspicious activity and alerts administrators but does not actively prevent the attack.

Intrusion Prevention System (IPS)

A network security device that monitors network traffic for malicious activity and automatically takes actions to prevent detected threats in real-time.

  • Actively blocks or drops malicious traffic.
  • Operates inline with network traffic.
  • Can use signature-based, anomaly-based, or policy-based detection.

Memory trick: IPS Prevents, IDS Detects, NAC Controls, Filters Block Content.

More Network Security questions