Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium

A security team is evaluating incident response capabilities and wants to implement a system that can automatically block known malicious IP addresses and domains at the network perimeter. Which of the following incident response tools would best fulfill this requirement?

  1. ASecurity Information and Event Management (SIEM)
  2. BThreat Intelligence Platform (TIP)
  3. CEndpoint Detection and Response (EDR)
  4. DNext-Generation Firewall (NGFW)
Show answer & explanation

Correct answer: D. Next-Generation Firewall (NGFW)

A Next-Generation Firewall (NGFW) is designed to perform deep packet inspection, application-level control, and integrate with threat intelligence to actively block known malicious IP addresses and domains at the network perimeter, providing advanced perimeter defense.

Why the other options are wrong

  • A. A SIEM aggregates logs but doesn't actively block traffic at the perimeter.
  • B. A TIP gathers and shares threat data but doesn't implement blocking itself.
  • C. EDR focuses on endpoint protection, not network perimeter blocking.

Next-Generation Firewall (NGFW)

An advanced firewall that combines traditional firewall functionalities with additional features like application awareness, intrusion prevention, and threat intelligence integration.

  • Performs deep packet inspection (DPI).
  • Can block traffic based on applications, users, and threat intelligence.
  • Operates at the network perimeter for ingress/egress filtering.

Memory trick: NGFW: Next-Gen Guard at the Network's Gate.

More Incident Handling questions