ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A company is implementing a new network-based Intrusion Detection System (IDS). To ensure the IDS can monitor all traffic traversing between the internal network and the internet without interfering with the traffic flow, where should the IDS sensor typically be placed?
- AIn front of the firewall, directly connected to the internet.
- BBetween the firewall and the internal router (or core switch), in a promiscuous mode.
- CBehind the main internal router, monitoring only internal LAN traffic.
- DOn every individual workstation as a host-based sensor.
Show answer & explanationAnswer & explanation
Correct answer: B. Between the firewall and the internal router (or core switch), in a promiscuous mode.
Placing a network-based IDS sensor between the firewall and the internal network allows it to monitor all inbound and outbound traffic that has been permitted by the firewall, without actively blocking or modifying the traffic itself. Operating in promiscuous mode ensures it sees all packets.
Why the other options are wrong
- A. Placing it in front of the firewall exposes it to raw internet traffic and might miss the context of firewall-filtered traffic.
- C. Behind the internal router would miss all inbound/outbound traffic at the perimeter, only seeing internal movements.
- D. This describes a Host-based IDS (HIDS), which monitors individual systems, not network perimeter traffic.
Intrusion Detection System (IDS)
A security system that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.
- Passively monitors traffic, does not block it.
- Detects anomalies, known attack signatures, or policy violations.
- Can be network-based (NIDS) or host-based (HIDS).
Memory trick: The IDS is a 'silent watcher' at the network's gate.