A network security administrator is deploying a Network Intrusion Detection System (NIDS) connected to a hardware network TAP at the main datacenter perimeter. Which of the following operational characteristics and limitations apply specifically to this out-of-band NIDS architecture? (Select TWO).
- The deployment introduces zero processing latency to the active transit traffic flow.Cevap
- The system cannot directly block or drop malicious packets before they reach their destination host.Cevap
- CThe monitoring sensor becomes a single point of failure that halts all network throughput if the sensor service crashes.
- DThe appliance decrypts Layer 7 HTTPS payload contents automatically without host-based certificate access.
Cevap
The out-of-band NIDS deployment introduces zero processing latency to live transit traffic and cannot directly drop or block malicious packets inline before they reach their destination.
Out-of-band NIDS sensors receive duplicate frames via SPAN or network TAPs. Because the sensor operates outside the live packet path, it does not add latency to transit traffic, but it also lacks the ability to prevent or drop malicious packets inline before they arrive at their destination.
Adım Adım Çözüm
Anahtar Kavram
Out-of-Band NIDS Architecture vs. Inline NIPS Placement