nerdexam
Cisco

352-001 · Question #443

A hosted service provider is designing an IPS solution to protect its DMZ segment. The goal is to detect and prevent anomalous activities and, at the same time, give the security operations team…

The correct answer is A. Deploy IPS as inline mode between the firewall and the servers. Inline IPS mode actively blocks threats in the traffic path, while promiscuous mode only detects. Positioning the IPS between the firewall and the DMZ servers ensures both prevention and SOC visibility for the protected segment.

Designing Security

Question

A hosted service provider is designing an IPS solution to protect its DMZ segment. The goal is to detect and prevent anomalous activities and, at the same time, give the security operations team visibility into any attempted attacks against the organization. Which IPS solution should you deploy in the Internet perimeter to accomplish this goal?

Options

  • ADeploy IPS as inline mode between the firewall and the servers
  • BDeploy IPS as promiscuous mode between the firewall and the servers
  • CDeploy IPS as inline mode between the firewall and the internet gateway
  • DDeploy IPS as promiscuous mode between the firewall and the internet gateway

How the community answered

(37 responses)
  • A
    78% (29)
  • B
    11% (4)
  • C
    3% (1)
  • D
    8% (3)

Why each option

Inline IPS mode actively blocks threats in the traffic path, while promiscuous mode only detects. Positioning the IPS between the firewall and the DMZ servers ensures both prevention and SOC visibility for the protected segment.

ADeploy IPS as inline mode between the firewall and the serversCorrect

Inline mode inserts the IPS directly into the traffic path so it can detect and drop malicious packets in real time, satisfying the prevention requirement. Placing it between the firewall and the servers scopes protection to the DMZ segment and gives the security operations team full visibility into all attack attempts directed at those hosts.

BDeploy IPS as promiscuous mode between the firewall and the servers

Promiscuous mode receives only a mirrored copy of traffic and can generate alerts but cannot block or drop packets in transit, failing the active prevention requirement.

CDeploy IPS as inline mode between the firewall and the internet gateway

Placing the IPS inline between the internet gateway and the firewall is upstream of the DMZ and does not specifically protect the DMZ servers.

DDeploy IPS as promiscuous mode between the firewall and the internet gateway

Promiscuous mode cannot actively prevent attacks, and positioning it upstream of the firewall does not target the DMZ segment.

Concept tested: IPS inline vs promiscuous mode deployment placement

Source: https://www.cisco.com/c/en/us/td/docs/security/ips/configuration/guide/cli/configguide/cli_mode.html

Topics

#IPS deployment#inline mode#DMZ security#network perimeter

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice