Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A security operations center (SOC) analyst is reviewing logs from an Intrusion Prevention System (IPS). The IPS has detected and blocked several attempts of a known exploit targeting a common vulnerability. Which core function of the IPS is being demonstrated in this scenario?
- ATraffic Shaping
- BAnomaly Detection
- CSignature-Based Detection
- DPolicy Enforcement
Show answer & explanationAnswer & explanation
Correct answer: C. Signature-Based Detection
When an IPS detects and blocks 'known exploits targeting a common vulnerability,' it is performing signature-based detection. This method relies on a database of known attack patterns (signatures) to identify and prevent threats. Anomaly detection looks for deviations from normal behavior. Policy enforcement is a broader term for acting on rules. Traffic shaping manages bandwidth, not threats.
Why the other options are wrong
- A. Traffic shaping is used to manage network bandwidth and prioritize traffic, unrelated to intrusion prevention.
- B. Anomaly detection identifies deviations from a baseline of normal network behavior, not specifically known exploits.
- D. Policy enforcement is a general term for applying rules, but not the specific detection mechanism being asked about.
Signature-Based Detection
Signature-based detection is a method used by IDS/IPS systems to identify and block threats by comparing network traffic or system activity against a database of known attack patterns or signatures.
- Relies on a database of known attack patterns.
- Effective against known exploits and malware.
- Can be bypassable by polymorphic or zero-day threats.
Memory trick: An IPS finds bad guys by their 'known faces' or 'weird behavior'.