Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy

A security operations center (SOC) analyst is reviewing logs from an Intrusion Prevention System (IPS). The IPS has detected and blocked several attempts of a known exploit targeting a common vulnerability. Which core function of the IPS is being demonstrated in this scenario?

  1. ATraffic Shaping
  2. BAnomaly Detection
  3. CSignature-Based Detection
  4. DPolicy Enforcement
Show answer & explanation

Correct answer: C. Signature-Based Detection

When an IPS detects and blocks 'known exploits targeting a common vulnerability,' it is performing signature-based detection. This method relies on a database of known attack patterns (signatures) to identify and prevent threats. Anomaly detection looks for deviations from normal behavior. Policy enforcement is a broader term for acting on rules. Traffic shaping manages bandwidth, not threats.

Why the other options are wrong

  • A. Traffic shaping is used to manage network bandwidth and prioritize traffic, unrelated to intrusion prevention.
  • B. Anomaly detection identifies deviations from a baseline of normal network behavior, not specifically known exploits.
  • D. Policy enforcement is a general term for applying rules, but not the specific detection mechanism being asked about.

Signature-Based Detection

Signature-based detection is a method used by IDS/IPS systems to identify and block threats by comparing network traffic or system activity against a database of known attack patterns or signatures.

  • Relies on a database of known attack patterns.
  • Effective against known exploits and malware.
  • Can be bypassable by polymorphic or zero-day threats.

Memory trick: An IPS finds bad guys by their 'known faces' or 'weird behavior'.

More Network Security questions