nerdexam
Cisco

210-250 · Question #89

Which three statements about host-based IPS are true? (Choose three)

The correct answer is A. It can view encrypted files D. It can have more restrictive policies than network-based IPS F. It can generate alerts based on behavior at the desktop level. Host-based IPS (HIPS) operates at the endpoint level, giving it unique visibility into encrypted data, desktop behavior, and host-specific policy enforcement.

Security Technologies

Question

Which three statements about host-based IPS are true? (Choose three)

Options

  • AIt can view encrypted files
  • BIt can be deployed at the perimeter
  • CIt uses signature-based policies
  • DIt can have more restrictive policies than network-based IPS
  • EIt works with deployed firewalls
  • FIt can generate alerts based on behavior at the desktop level.

How the community answered

(56 responses)
  • A
    71% (40)
  • B
    9% (5)
  • C
    16% (9)
  • E
    4% (2)

Why each option

Host-based IPS (HIPS) operates at the endpoint level, giving it unique visibility into encrypted data, desktop behavior, and host-specific policy enforcement.

AIt can view encrypted filesCorrect

Because HIPS operates on the host itself, it can inspect files and processes after decryption occurs in memory, giving it visibility that network-based IPS lacks when traffic is encrypted.

BIt can be deployed at the perimeter

HIPS is installed on individual endpoints to protect those specific hosts; perimeter deployment is the role of network-based IPS or firewalls.

CIt uses signature-based policies

While HIPS can use signatures, it is primarily distinguished by behavioral and anomaly-based detection; signature-based policies alone are more characteristic of network-based IPS, and this is not one of the three defining true statements.

DIt can have more restrictive policies than network-based IPSCorrect

HIPS policies are applied per host, allowing administrators to enforce stricter rules tailored to a specific system's role or risk profile compared to the broader policies of a network IPS.

EIt works with deployed firewalls

HIPS operates independently on the host and does not require or depend on deployed firewalls to function; its protection is self-contained at the endpoint.

FIt can generate alerts based on behavior at the desktop level.Correct

HIPS monitors OS calls, application behavior, and user activity directly on the endpoint, enabling it to generate alerts based on suspicious behavior observed at the desktop level.

Concept tested: Host-based IPS capabilities vs. network-based IPS

Source: https://www.cisco.com/c/en/us/products/security/host-based-intrusion-prevention-systems/index.html

Topics

#HIPS#host-based IPS#encrypted file inspection#behavior-based detection

Community Discussion

No community discussion yet for this question.

Full 210-250 Practice