Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A network security team is designing a defense strategy against various types of attacks, including reconnaissance, denial-of-service, and malware propagation. They decide to implement a system that can both detect malicious activity and actively block or prevent it in real-time. Which technology best fits this description?

  1. AIntrusion Prevention System (IPS)
  2. BNetwork Access Control (NAC)
  3. CSecurity Information and Event Management (SIEM)
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: A. Intrusion Prevention System (IPS)

An Intrusion Prevention System (IPS) is designed to actively monitor network traffic for malicious activity and automatically block or prevent detected threats in real-time. This combines the detection capabilities of an IDS with active prevention, directly addressing the requirement.

Why the other options are wrong

  • B. NAC controls who and what can connect to the network, not real-time threat prevention on ongoing traffic.
  • C. A SIEM aggregates and analyzes security logs to provide insights but does not perform real-time blocking.
  • D. An IDS detects and alerts on malicious activity but does not actively block it.

Intrusion Prevention System (IPS)

A network security device that monitors network traffic for malicious activity and can automatically take action to block or prevent detected threats in real-time.

  • Actively blocks or prevents intrusions.
  • Combines detection with prevention capabilities.
  • Operates in-line with network traffic.
  • Protects against a wide range of attacks including DoS, malware, and exploits.

Memory trick: IPS: The active bouncer that both spots and stops trouble.

More Network Security questions