Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A company is experiencing slow network performance and intermittent service outages. A preliminary investigation reveals unusual outbound traffic to various external IP addresses, as well as a significant increase in DNS queries originating from internal workstations. The security team suspects a large number of internal machines might be infected and participating in a botnet. Which security control is primarily designed to detect and prevent such command-and-control (C2) communications?

  1. AData Loss Prevention (DLP)
  2. BWeb Application Firewall (WAF)
  3. CEndpoint Detection and Response (EDR)
  4. DIntrusion Prevention System (IPS)
Show answer & explanation

Correct answer: D. Intrusion Prevention System (IPS)

An Intrusion Prevention System (IPS) is designed to monitor network traffic for malicious activity and can actively block suspicious C2 communications based on signatures, behavioral analysis, or known bad IP addresses, thus preventing botnet control.

Why the other options are wrong

  • A. DLP focuses on preventing sensitive data exfiltration, not C2 traffic.
  • B. WAF protects web applications from attacks, not general network C2 traffic.
  • C. EDR focuses on endpoint-level detection and response, while IPS operates at the network level for C2 prevention.

Intrusion Prevention System (IPS)

A network security device that monitors network and/or system activities for malicious or unwanted behavior and can react in real-time to block or prevent those activities.

  • Active prevention of attacks.
  • Operates inline with network traffic.
  • Detects and blocks known malicious patterns (signatures) and anomalies.

Memory trick: To stop the bad stuff mid-flow, you need active guards on the network.

More Cybersecurity Fundamentals questions