Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A network security analyst is tasked with deploying a new network intrusion detection system (NIDS) in a critical segment of the corporate network. The NIDS needs to monitor all traffic passively without introducing latency or altering network packets. Which deployment mode is most appropriate for this requirement?
- AIn-line mode with fail-open
- BProxy mode
- CSPAN/Mirror port mode
- DTap mode (active)
Show answer & explanationAnswer & explanation
Correct answer: C. SPAN/Mirror port mode
SPAN (Switched Port Analyzer) or mirror port mode allows a NIDS to receive a copy of all network traffic passing through a switch port without being directly in the data path. This ensures passive monitoring without latency or packet alteration.
Why the other options are wrong
- A. In-line mode places the NIDS directly in the traffic path, introducing latency and potentially altering packets, contrary to the requirement.
- B. Proxy mode acts as an intermediary for connections, actively altering traffic flow and introducing latency, which is not suitable.
- D. An active tap (network tap) can also be in-line, similar to in-line mode, or used passively. However, 'SPAN/Mirror port mode' specifically denotes passive monitoring via a switch feature, which is the most common and direct answer for this scenario.
NIDS Passive Deployment
A method of deploying a Network Intrusion Detection System (NIDS) where it monitors network traffic by receiving a copy of the data, rather than being placed directly in the data path, thus avoiding impact on network performance.
- Uses SPAN/mirror ports or network taps
- Zero latency or packet alteration
- Ideal for monitoring without intervention
Memory trick: NIDS: Span for Passive, Inline for Active.