A network security administrator needs to deploy a security solution that sits directly in the traffic path to inspect incoming packets and actively block identified threats in real time before they reach internal hosts. Which of the following devices should the administrator implement?
- Network Intrusion Prevention System (NIPS) placed inlineCevap
- BNetwork Intrusion Detection System (NIDS) connected to a switch SPAN port
- CProtocol analyzer installed on a mirrored port interface
- DHost-based Antivirus engine examining local system file integrity
Cevap
Network Intrusion Prevention System (NIPS) placed inline
An inline Network Intrusion Prevention System (NIPS) processes traffic directly in the flow path, enabling automated real-time threat detection and packet drop actions before malicious traffic reaches target nodes.
Adım Adım Çözüm
Anahtar Kavram
Intrusion Prevention Systems (IPS) operate inline to actively block detected threats in real time, whereas Intrusion Detection Systems (IDS) operate passively out-of-band to monitor and alert.