Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A company is upgrading its network infrastructure and wants to implement a solution that can identify and block malicious traffic before it reaches internal systems, based on known attack signatures and behavioral anomalies. The solution should also be able to inspect encrypted traffic. Which security technology best fits this description?
- AStateful Firewall
- BLoad Balancer
- CProxy Server
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: D. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) actively monitors network traffic for malicious activity (signatures, anomalies) and can block threats in real-time. Modern IPS devices often have the capability to decrypt and inspect encrypted traffic (SSL/TLS inspection) to identify hidden threats.
Why the other options are wrong
- A. A stateful firewall primarily filters traffic based on rules and connection state, but typically lacks advanced signature/anomaly detection and deep encrypted traffic inspection capabilities of an IPS.
- B. A load balancer distributes network traffic across multiple servers to ensure optimal resource utilization and availability, not for security threat detection and prevention.
- C. A proxy server acts as an intermediary for requests from clients seeking resources from other servers; while it can filter, its primary role isn't real-time, signature-based intrusion prevention.
Intrusion Prevention System (IPS)
An IPS is a network security device that monitors network and/or system activities for malicious policy violations and can automatically take actions to prevent detected threats.
- Actively blocks malicious traffic
- Uses signatures and behavioral analysis
- Can perform SSL/TLS inspection
Memory trick: IPS actively prevents trouble, unlike an IDS that just watches.