Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium

A security operations center (SOC) analyst is investigating a series of suspicious login attempts originating from various IP addresses globally, targeting multiple internal services. The attempts show a pattern of brute-force attacks. Which visibility and enforcement technology would provide the most effective real-time detection and automated response to block these types of threats?

  1. ABasic Stateful Firewall
  2. BPort Address Translation (PAT)
  3. CNetwork Intrusion Prevention System (NIPS)
  4. DStandard Access Control Lists (ACLs)
Show answer & explanation

Correct answer: C. Network Intrusion Prevention System (NIPS)

A Network Intrusion Prevention System (NIPS) is specifically designed to detect and automatically block malicious activities, such as brute-force attacks, in real time by analyzing network traffic against known signatures and behavioral patterns.

Why the other options are wrong

  • A. A basic stateful firewall primarily controls traffic based on configured rules and connection state, but lacks advanced threat detection and automated blocking capabilities for brute-force attacks.
  • B. PAT is a form of NAT and does not provide any security detection or enforcement against brute-force attacks.
  • D. Standard ACLs provide basic packet filtering based on IP addresses and ports, without dynamic threat detection or automated response capabilities.

Network Intrusion Prevention System (NIPS)

A network security device that monitors network traffic for malicious activity, logs information about such activity, attempts to block it, and reports it.

  • Operates in-line, actively blocking threats.
  • Uses signatures, anomaly detection, and policy enforcement.
  • Protects against various attacks like brute-force, DoS, exploits.

Memory trick: Detect and Prevent, stay vigilant and defend.

More Visibility and Enforcement questions