Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A security team is evaluating incident response capabilities and wants to implement a system that can automatically block known malicious IP addresses and domains at the network perimeter. Which of the following incident response tools would best fulfill this requirement?
- ASecurity Information and Event Management (SIEM)
- BThreat Intelligence Platform (TIP)
- CEndpoint Detection and Response (EDR)
- DNext-Generation Firewall (NGFW)
Show answer & explanationAnswer & explanation
Correct answer: D. Next-Generation Firewall (NGFW)
A Next-Generation Firewall (NGFW) is designed to perform deep packet inspection, application-level control, and integrate with threat intelligence to actively block known malicious IP addresses and domains at the network perimeter, providing advanced perimeter defense.
Why the other options are wrong
- A. A SIEM aggregates logs but doesn't actively block traffic at the perimeter.
- B. A TIP gathers and shares threat data but doesn't implement blocking itself.
- C. EDR focuses on endpoint protection, not network perimeter blocking.
Next-Generation Firewall (NGFW)
An advanced firewall that combines traditional firewall functionalities with additional features like application awareness, intrusion prevention, and threat intelligence integration.
- Performs deep packet inspection (DPI).
- Can block traffic based on applications, users, and threat intelligence.
- Operates at the network perimeter for ingress/egress filtering.
Memory trick: NGFW: Next-Gen Guard at the Network's Gate.