210-260 · Question #51
When an IPS detects an attack, which action can the IPS take to prevent the attack from spreading?
The correct answer is D. Deny the connection inline. This action prevents the attacker from communicating with the victim on any port. However, the attacker could communicate with other hosts, making this action better suited for exploits that target a specific host. This event action is appropriate when the likelihood of a false…
Question
When an IPS detects an attack, which action can the IPS take to prevent the attack from spreading?
Options
- APerform a Layer 6 reset
- BDeploy an antimalware system
- CEnable bypass mode
- DDeny the connection inline
How the community answered
(46 responses)- A4% (2)
- C2% (1)
- D93% (43)
Explanation
This action prevents the attacker from communicating with the victim on any port. However, the attacker could communicate with other hosts, making this action better suited for exploits that target a specific host. This event action is appropriate when the likelihood of a false alarm or spoofing is minimal.
Topics
Community Discussion
No community discussion yet for this question.