Soru

Zorluk: OrtaIntrusion Detection and Prevention Systems (IDS/IPS)

A network security team is transitioning from a passive out-of-band Network Intrusion Detection System (NIDS) TAP interface to an active in-band Network Intrusion Prevention System (NIPS) on an enterprise perimeter connection. Which of the following represent key operational advantages or trade-offs specific to deploying an inline NIPS compared to a passive NIDS? (Select TWO.)

  1. An inline NIPS can drop malicious packets in real time before they reach their destination host.Cevap
  2. An inline NIPS introduces potential latency and can become a single point of failure if bypass mechanisms fail.Cevap
  3. C
    An inline NIPS processes duplicated frame copies without adding processing delay or risking network interruption.
  4. D
    An inline NIPS eliminates the need for signature updates because in-band placement inherently decrypts TLS traffic.

Cevap

The correct statements are that an inline NIPS can drop malicious packets in real time before reaching the destination, and that in-band placement introduces potential latency and single-point-of-failure risks if bypass hardware is absent.
Deploying an Intrusion Prevention System in-band (inline) means all packets flow through the device. This allows the system to actively prevent attacks by dropping malicious packets in real time. However, because it sits directly in the communication path, it adds packet processing latency and creates a potential single point of failure if the device crashes or lacks bypass capabilities.

Adım Adım Çözüm

1
Analyze the structural placement difference between inline NIPS (in-band) and passive NIDS (out-of-band).
Inline NIPS devices sit directly along the network path, whereas passive NIDS monitors mirrored copy traffic via TAP or SPAN ports.
Placement determines whether the system can actively alter live traffic or only inspect copied traffic.
2
Evaluate the real-time prevention capability.
Being in-band allows the NIPS to inspect and drop or reset malicious connections before packets reach target devices.
This active prevention capability is the primary operational advantage of NIPS over NIDS.
3
Evaluate the hardware and throughput implications of inline placement.
Since every packet must pass through the NIPS engine, hardware latency is introduced, and device failure can sever the link if fail-open/bypass mechanisms are not configured.
This represents the primary trade-off when moving from zero-impact passive monitoring to inline prevention.

Anahtar Kavram

Inline NIPS vs Passive NIDS Operational Trade-offs
Bu soruyu puanla