Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy

A network security analyst is tasked with deploying a new network intrusion detection system (NIDS) in a critical segment of the corporate network. The NIDS needs to monitor all traffic passively without introducing latency or altering network packets. Which deployment mode is most appropriate for this requirement?

  1. AIn-line mode with fail-open
  2. BProxy mode
  3. CSPAN/Mirror port mode
  4. DTap mode (active)
Show answer & explanation

Correct answer: C. SPAN/Mirror port mode

SPAN (Switched Port Analyzer) or mirror port mode allows a NIDS to receive a copy of all network traffic passing through a switch port without being directly in the data path. This ensures passive monitoring without latency or packet alteration.

Why the other options are wrong

  • A. In-line mode places the NIDS directly in the traffic path, introducing latency and potentially altering packets, contrary to the requirement.
  • B. Proxy mode acts as an intermediary for connections, actively altering traffic flow and introducing latency, which is not suitable.
  • D. An active tap (network tap) can also be in-line, similar to in-line mode, or used passively. However, 'SPAN/Mirror port mode' specifically denotes passive monitoring via a switch feature, which is the most common and direct answer for this scenario.

NIDS Passive Deployment

A method of deploying a Network Intrusion Detection System (NIDS) where it monitors network traffic by receiving a copy of the data, rather than being placed directly in the data path, thus avoiding impact on network performance.

  • Uses SPAN/mirror ports or network taps
  • Zero latency or packet alteration
  • Ideal for monitoring without intervention

Memory trick: NIDS: Span for Passive, Inline for Active.

More Network Intrusion Analysis questions