Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium
A security operations center (SOC) analyst is investigating a series of suspicious login attempts originating from various IP addresses globally, targeting multiple internal services. The attempts show a pattern of brute-force attacks. Which visibility and enforcement technology would provide the most effective real-time detection and automated response to block these types of threats?
- ABasic Stateful Firewall
- BPort Address Translation (PAT)
- CNetwork Intrusion Prevention System (NIPS)
- DStandard Access Control Lists (ACLs)
Show answer & explanationAnswer & explanation
Correct answer: C. Network Intrusion Prevention System (NIPS)
A Network Intrusion Prevention System (NIPS) is specifically designed to detect and automatically block malicious activities, such as brute-force attacks, in real time by analyzing network traffic against known signatures and behavioral patterns.
Why the other options are wrong
- A. A basic stateful firewall primarily controls traffic based on configured rules and connection state, but lacks advanced threat detection and automated blocking capabilities for brute-force attacks.
- B. PAT is a form of NAT and does not provide any security detection or enforcement against brute-force attacks.
- D. Standard ACLs provide basic packet filtering based on IP addresses and ports, without dynamic threat detection or automated response capabilities.
Network Intrusion Prevention System (NIPS)
A network security device that monitors network traffic for malicious activity, logs information about such activity, attempts to block it, and reports it.
- Operates in-line, actively blocking threats.
- Uses signatures, anomaly detection, and policy enforcement.
- Protects against various attacks like brute-force, DoS, exploits.
Memory trick: Detect and Prevent, stay vigilant and defend.