Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A network security team is designing a defense strategy against various types of attacks, including reconnaissance, denial-of-service, and malware propagation. They decide to implement a system that can both detect malicious activity and actively block or prevent it in real-time. Which technology best fits this description?
- AIntrusion Prevention System (IPS)
- BNetwork Access Control (NAC)
- CSecurity Information and Event Management (SIEM)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: A. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) is designed to actively monitor network traffic for malicious activity and automatically block or prevent detected threats in real-time. This combines the detection capabilities of an IDS with active prevention, directly addressing the requirement.
Why the other options are wrong
- B. NAC controls who and what can connect to the network, not real-time threat prevention on ongoing traffic.
- C. A SIEM aggregates and analyzes security logs to provide insights but does not perform real-time blocking.
- D. An IDS detects and alerts on malicious activity but does not actively block it.
Intrusion Prevention System (IPS)
A network security device that monitors network traffic for malicious activity and can automatically take action to block or prevent detected threats in real-time.
- Actively blocks or prevents intrusions.
- Combines detection with prevention capabilities.
- Operates in-line with network traffic.
- Protects against a wide range of attacks including DoS, malware, and exploits.
Memory trick: IPS: The active bouncer that both spots and stops trouble.