ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A global company uses a distributed network architecture with data centers and branch offices across different continents. They need a solution that can identify and block known malicious traffic patterns and signatures at the network perimeter before they reach internal systems, acting proactively. Which network security device is best suited for this proactive threat prevention?
- ASwitch
- BRouter
- CIntrusion Prevention System (IPS)
- DLoad Balancer
Show answer & explanationAnswer & explanation
Correct answer: C. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) actively monitors network traffic for malicious activity or policy violations and can automatically take action to block or prevent detected threats in real-time, making it ideal for proactive threat prevention at the network perimeter.
Why the other options are wrong
- A. A switch connects devices within a local network and operates at Layer 2, without threat detection capabilities.
- B. A router forwards packets between networks but doesn't typically inspect content for malicious patterns.
- D. A load balancer distributes network traffic to optimize resource utilization, not for security threat prevention.
Intrusion Prevention System (IPS)
A network security device that monitors network and/or system activities for malicious policy violations or known attack patterns and can automatically block or prevent detected threats.
- Proactively blocks malicious traffic.
- Uses signature-based and anomaly-based detection.
- Operates in-line with network traffic.
- Can prevent attacks like malware, DoS, and exploits.
Memory trick: IPS is the 'security guard' that not only spots trouble but immediately 'stops' it at the gate.