ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A cybersecurity team is concerned about the increasing sophistication of malware that can evade traditional signature-based antivirus solutions. They want to implement a solution that can detect and prevent threats based on suspicious behavior, even if the specific malware signature is unknown. Which technology would best address this requirement?
- AIntrusion Prevention System (IPS) with behavioral analysis
- BNetwork Access Control (NAC)
- CLoad Balancer
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion Prevention System (IPS) with behavioral analysis
An Intrusion Prevention System (IPS) with behavioral analysis capabilities is designed to detect and prevent threats based on anomalous activities and suspicious patterns, rather than relying solely on known signatures. This allows it to identify zero-day exploits and polymorphic malware effectively.
Why the other options are wrong
- B. NAC controls network access based on device compliance and user authentication, not advanced malware detection.
- C. A load balancer distributes network traffic across multiple servers to improve performance and reliability, unrelated to threat detection.
- D. DLP focuses on preventing sensitive data from leaving the organization, not on detecting advanced malware itself.
Intrusion Prevention System (IPS)
A network security device that monitors network and/or system activities for malicious policy violations and can react in real-time to block or prevent those activities.
- Actively blocks or prevents detected threats.
- Can use signature-based, anomaly-based, or behavioral detection.
- Placed in-line with network traffic flow.
Memory trick: Behavioral IPS is the smart guard, spotting suspicious actions, not just known faces.