200-201 · Question #454
A security engineer must implement IPS inside a DMZ organization. One of the requirements is to be able to block suspicious traffic based on a triggered signature in real life. IPS will be connected…
The correct answer is C. inline. An inline deployment is required for an IPS (Intrusion Prevention System) to actively block suspicious traffic in real-time based on triggered signatures. In this setup, the IPS is placed directly in the traffic path, allowing it to inspect and either allow or block traffic as…
Question
A security engineer must implement IPS inside a DMZ organization. One of the requirements is to be able to block suspicious traffic based on a triggered signature in real life. IPS will be connected behind DMZ firewalls directly to core switches. Which traffic integration must be done to complete this project?
Options
- Apassive
- Bmirroring
- Cinline
- Dtap
How the community answered
(31 responses)- A3% (1)
- B13% (4)
- C77% (24)
- D6% (2)
Explanation
An inline deployment is required for an IPS (Intrusion Prevention System) to actively block suspicious traffic in real-time based on triggered signatures. In this setup, the IPS is placed directly in the traffic path, allowing it to inspect and either allow or block traffic as it flows through the network. This is essential for fulfilling the requirement of blocking malicious traffic in real life.
Topics
Community Discussion
No community discussion yet for this question.