CAS-001 · Question #409
The risk manager has requested a security solution that is centrally managed, can easily be updated, and protects end users' workstations from both known and unknown malicious attacks when connected…
The correct answer is A. HIPS. A Host-based Intrusion Prevention System (HIPS) is installed directly on the endpoint (workstation), meaning it protects the device regardless of which network it is connected to-whether the corporate office network or a home network. HIPS can be centrally managed via a…
Question
The risk manager has requested a security solution that is centrally managed, can easily be updated, and protects end users' workstations from both known and unknown malicious attacks when connected to either the office or home network. Which of the following would BEST meet this requirement?
Options
- AHIPS
- BUTM
- CAntivirus
- DNIPS
- EDLP
How the community answered
(17 responses)- A88% (15)
- C6% (1)
- D6% (1)
Explanation
A Host-based Intrusion Prevention System (HIPS) is installed directly on the endpoint (workstation), meaning it protects the device regardless of which network it is connected to-whether the corporate office network or a home network. HIPS can be centrally managed via a management console, receives signature and rule updates from a central server, and uses both signature-based and behavioral/heuristic detection to protect against both known and unknown (zero-day) threats. UTM (B) and NIPS (D) are network-based appliances that only protect devices while they are on the corporate network-they provide no coverage when employees work from home. Antivirus (C) primarily detects known threats via signatures and is weaker against unknown attacks. DLP (E) is focused on preventing data leakage, not blocking malicious attacks.
Topics
Community Discussion
No community discussion yet for this question.