nerdexam
Cisco

210-260 · Question #51

When an IPS detects an attack, which action can the IPS take to prevent the attack from spreading?

The correct answer is D. Deny the connection inline. This action prevents the attacker from communicating with the victim on any port. However, the attacker could communicate with other hosts, making this action better suited for exploits that target a specific host. This event action is appropriate when the likelihood of a false…

IPS

Question

When an IPS detects an attack, which action can the IPS take to prevent the attack from spreading?

Options

  • APerform a Layer 6 reset
  • BDeploy an antimalware system
  • CEnable bypass mode
  • DDeny the connection inline

How the community answered

(46 responses)
  • A
    4% (2)
  • C
    2% (1)
  • D
    93% (43)

Explanation

This action prevents the attacker from communicating with the victim on any port. However, the attacker could communicate with other hosts, making this action better suited for exploits that target a specific host. This event action is appropriate when the likelihood of a false alarm or spoofing is minimal.

Topics

#IPS response actions#inline mode#deny connection#attack mitigation

Community Discussion

No community discussion yet for this question.

Full 210-260 Practice