Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium

A company's email server is experiencing a Denial of Service (DoS) attack, causing widespread email outages. The incident response team has identified the source IP addresses of the attack. Which of the following incident response tools would be most effective in immediately mitigating this attack by blocking the malicious traffic?

  1. ASecurity Information and Event Management (SIEM)
  2. BData Loss Prevention (DLP) system
  3. CNetwork Intrusion Prevention System (NIPS)
  4. DVulnerability Management System (VMS)
Show answer & explanation

Correct answer: C. Network Intrusion Prevention System (NIPS)

A Network Intrusion Prevention System (NIPS) is designed to actively monitor network traffic for malicious activity and automatically take action to block or prevent such traffic, making it ideal for immediate DoS mitigation by blocking identified source IP addresses.

Why the other options are wrong

  • A. A SIEM collects and analyzes logs but does not actively block traffic.
  • B. DLP prevents data exfiltration, not DoS attacks.
  • D. A VMS identifies vulnerabilities but does not mitigate active attacks.

Network Intrusion Prevention System (NIPS)

A security tool that monitors network traffic for malicious activity and actively blocks or prevents detected threats in real-time.

  • Operates in-line with network traffic.
  • Can block malicious packets or connections.
  • Effective against various attacks, including DoS and exploits.

Memory trick: NIPS: Network's In-line Protector, Stopping Bad Stuff.

More Incident Handling questions