Soru

Zorluk: ZorIntrusion Detection and Prevention Systems (IDS/IPS)

A network security team is designing a monitoring strategy for a high-frequency trading subnetwork and a remote branch office. The trading network requires absolute zero added latency on active traffic paths while maintaining detection capability for novel, unknown protocol exploits. Meanwhile, the branch office needs comprehensive visibility into mirrored VLAN traffic captured by a switch SPAN port. Which of the following design choices correctly fulfill these architecture and detection requirements? (Select TWO)

  1. Deploying an out-of-band Network Intrusion Detection System (NIDS) connected to a switch SPAN port allows passive traffic analysis without introducing packet processing delays to active network streams.Cevap
  2. Implementing anomaly-based detection mechanisms enables the security system to identify zero-day attacks by detecting deviations from an established baseline of normal network behavior.Cevap
  3. C
    Placing an inline Network Intrusion Prevention System (NIPS) directly in the active traffic path of the trading network to eliminate latency during peak transmission volumes.
  4. D
    Configuring signature-based detection as the sole inspection logic to automatically identify previously unencountered zero-day vulnerabilities across encrypted application sessions.

Cevap

The correct architectural choices are deploying an out-of-band NIDS via SPAN ports for zero-latency passive visibility and implementing anomaly-based detection mechanisms to identify unknown zero-day threats.
Out-of-band NIDS connected via SPAN or network TAP receives duplicate frames, providing passive security monitoring without inserting processing overhead into active network paths. Furthermore, anomaly-based (or behavior-based) detection compares current traffic against historical baseline metrics, enabling the identification of unknown zero-day attacks that lack established signatures.

Adım Adım Çözüm

1
Analyze deployment topology requirements for low-latency network segments
In-band (inline) NIPS devices inspect packets synchronously and introduce queueing latency, whereas out-of-band NIDS passively analyzes frame copies mirrored via SPAN/TAP without impacting inline latency.
Out-of-band placement preserves original packet timing on high-frequency trading lines.
2
Evaluate detection engine logic for identifying unknown attacks
Signature-based detection matches traffic against known malicious patterns and fails against zero-day threats. Anomaly-based detection compares real-time traffic to a baseline profile to flag unexpected behavior.
Novel zero-day exploits lack pre-defined signature patterns and require statistical anomaly detection.

Anahtar Kavram

Passive out-of-band IDS placement versus inline IPS prevention, and anomaly-based baseline detection versus signature matching.
Bu soruyu puanla