Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A network security engineer is deploying a new intrusion prevention system (IPS) to protect critical internal servers. After initial deployment, legitimate applications are experiencing intermittent connectivity issues and slow performance. Further investigation reveals that the IPS is dropping packets for these applications. What is the most likely cause of this issue?
- AHardware failure in the IPS device
- BInsufficient network bandwidth
- COverly aggressive IPS policies
- DIncorrect IPS signature updates
Show answer & explanationAnswer & explanation
Correct answer: C. Overly aggressive IPS policies
When an IPS causes legitimate traffic to be dropped, it typically indicates that its detection policies are too strict or 'overly aggressive,' leading to false positives. This is a common issue during initial IPS tuning.
Why the other options are wrong
- A. Hardware failure would likely result in complete outage or consistent, rather than intermittent, issues across all traffic, or the IPS bypassing traffic entirely.
- B. Insufficient network bandwidth might cause slow performance but wouldn't typically lead to an IPS dropping legitimate packets unless it's overwhelmed and dropping traffic as a failsafe.
- D. Incorrect signature updates could cause missed detections or new false positives, but general 'intermittent connectivity issues' for legitimate apps points more to broad policy issues.
IPS False Positive
An IPS false positive occurs when an Intrusion Prevention System incorrectly identifies legitimate network traffic or activity as malicious and takes preventive action, such as dropping packets.
- Leads to disruption of legitimate services.
- Requires careful tuning of IPS policies and signatures.
- A balance between security and availability must be achieved.
Memory trick: Too aggressive IPS: like an overzealous bouncer blocking VIPs.