Soru

Zorluk: KolayIntrusion Detection and Prevention Systems (IDS/IPS)

A security team is evaluating the operational differences between placing a Network Intrusion Detection System (NIDS) passively via a switch SPAN port versus deploying a Network Intrusion Prevention System (NIPS) inline. Which of the following statements accurately describe these deployment models? (Select TWO.)

  1. Inline NIPS placement allows the security appliance to actively stop threat vectors by dropping malicious packets in real time.Cevap
  2. Passive NIDS monitoring via a SPAN port inspects mirrored network traffic without adding inline latency to production network traffic.Cevap
  3. C
    Passive NIDS connected to a SPAN port operates purely at Layer 2 to physically block rogue packets before they reach destination network interfaces.
  4. D
    Inline NIPS deep packet inspection requires target network streams to be directed exclusively to TCP port 22 for packet analysis.

Cevap

The statement explaining that inline NIPS placement actively drops malicious packets in real time, along with the statement indicating that passive NIDS monitoring via a SPAN port inspects copied traffic without adding latency, are both correct.
Inline NIPS devices sit directly within the communication stream, enabling active packet drops upon detecting malicious traffic. Conversely, passive NIDS deployment receives mirrored traffic via switch SPAN ports, providing threat detection visibility without introducing inline processing latency.

Adım Adım Çözüm

1
Analyze NIPS inline placement features.
Inline placement puts the prevention device directly in the physical or logical flow of network traffic, enabling active mitigation such as packet dropping.
Traffic must pass through an inline device, allowing immediate inline action upon threat detection.
2
Analyze NIDS passive (out-of-band) placement features.
Out-of-band passive monitoring inspects mirrored traffic streams provided by SPAN ports or network TAPs without impacting packet forwarding latency.
Since traffic is mirrored, the NIDS operates in parallel to active network transmission.

Anahtar Kavram

In-band inline prevention versus out-of-band passive detection deployment models.
Bu soruyu puanla