ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A large organization with multiple branch offices needs a solution to monitor network traffic for suspicious activity and automatically block known attack patterns in real-time. Which network security device is best suited for both detecting and preventing such malicious activities?
- AContent Filter
- BIntrusion Prevention System (IPS)
- CNetwork Access Control (NAC)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: B. Intrusion Prevention System (IPS)
An IPS actively monitors network traffic for malicious activity and can take automated actions, such as blocking traffic, to prevent attacks in real-time.
Why the other options are wrong
- A. A content filter blocks access to specific websites or content types, not general attack patterns.
- C. NAC controls which devices can connect to the network but doesn't actively detect and block ongoing attacks.
- D. An IDS detects suspicious activity and alerts administrators but does not actively prevent the attack.
Intrusion Prevention System (IPS)
A network security device that monitors network traffic for malicious activity and automatically takes actions to prevent detected threats in real-time.
- Actively blocks or drops malicious traffic.
- Operates inline with network traffic.
- Can use signature-based, anomaly-based, or policy-based detection.
Memory trick: IPS Prevents, IDS Detects, NAC Controls, Filters Block Content.