Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsHard

A security administrator is implementing a system to proactively monitor network traffic for suspicious patterns and known attack signatures. If such activity is detected, the system should automatically block the malicious traffic and alert the administrator without requiring manual intervention for each incident. Which network security technology best fits this description?

  1. AIntrusion Detection System (IDS)
  2. BIntrusion Prevention System (IPS)
  3. CFirewall
  4. DProxy server
Show answer & explanation

Correct answer: B. Intrusion Prevention System (IPS)

An Intrusion Prevention System (IPS) not only detects suspicious activity and known attack signatures (like an IDS) but also takes active measures to block or prevent the malicious traffic in real-time. The key phrase 'automatically block the malicious traffic and alert the administrator without requiring manual intervention' points directly to the preventative capabilities of an IPS.

Why the other options are wrong

  • A. An IDS detects and alerts but does not automatically block traffic.
  • C. A firewall primarily filters traffic based on predefined rules (ports, IPs), but doesn't typically analyze content for attack signatures or proactively block in the same way an IPS does.
  • D. A proxy server acts as an intermediary for requests from clients seeking resources from other servers, not primarily for intrusion prevention.

Intrusion Prevention System (IPS)

A network security technology that monitors network traffic for malicious activity and automatically takes action to prevent identified threats.

  • Detects and prevents attacks in real-time.
  • Operates in-line (between traffic source and destination).
  • Can block, drop, or reset connections.

Memory trick: Detection is seeing trouble, Prevention is stopping it.

More Security Fundamentals questions