700-765 · Question #45
Which are two main features of Intrusion Prevention? (Choose two.)
The correct answer is A. Threat analysis through network behavior analysis D. Vulnerability-based threat management. Intrusion Prevention Systems (IPS) operate primarily through network behavior analysis to identify anomalies and use vulnerability-based detection to match threats against known exploit patterns.
Question
Which are two main features of Intrusion Prevention? (Choose two.)
Options
- AThreat analysis through network behavior analysis
- BProtecting against Zero-Day attacks
- CLayer-4 traffic monitoring across platforms
- DVulnerability-based threat management
How the community answered
(38 responses)- A87% (33)
- B5% (2)
- C8% (3)
Why each option
Intrusion Prevention Systems (IPS) operate primarily through network behavior analysis to identify anomalies and use vulnerability-based detection to match threats against known exploit patterns.
Network behavior analysis is a core IPS mechanism that establishes a baseline of normal traffic and flags deviations, enabling detection of threats like port scans, floods, and protocol anomalies.
Zero-day attack protection is associated with advanced sandboxing or threat intelligence solutions like Cisco AMP, not a primary IPS feature, since IPS relies on known signatures and cannot inherently detect unknown exploits.
Layer-4 traffic monitoring is specifically associated with Cisco's Layer-4 Traffic Monitor feature in web security appliances (WSA/Umbrella), not a defining feature of IPS.
IPS engines are fundamentally vulnerability-based - they match traffic against signatures tied to specific CVEs and known exploit patterns, making vulnerability management a defining IPS characteristic.
Concept tested: Core Intrusion Prevention System capabilities
Source: https://www.cisco.com/c/en/us/products/security/intrusion-prevention-system-ips/index.html
Topics
Community Discussion
No community discussion yet for this question.