GSLC · Question #362
Which system is designed to analyze, detect, and report on security-related events?
The correct answer is B. NIPS. NIPS monitors network traffic to analyze, detect, and report on security events, operating inline across the network.
Question
Which system is designed to analyze, detect, and report on security-related events?
Options
- AHIPS
- BNIPS
- CNIDS
- DHIDS
How the community answered
(21 responses)- A5% (1)
- B90% (19)
- C5% (1)
Why each option
NIPS monitors network traffic to analyze, detect, and report on security events, operating inline across the network.
HIPS (Host-based Intrusion Prevention System) operates on a single host rather than monitoring network-wide traffic, so it cannot report on events across the broader network.
NIPS (Network Intrusion Prevention System) is deployed inline on the network and is designed to monitor, analyze, and report on security-related events across network traffic in real time. It inspects packets flowing through the network segment and generates alerts and reports on detected threats. Its network-wide scope makes it the appropriate system for broad security event analysis and reporting across multiple hosts.
NIDS (Network Intrusion Detection System) is a passive system that only detects and reports without taking preventive action, making it a subset of what NIPS offers.
HIDS (Host-based Intrusion Detection System) monitors activity only on the individual host where it is installed, not across the network.
Concept tested: Network intrusion prevention system roles and capabilities
Source: https://www.nist.gov/publications/guide-intrusion-detection-and-prevention-systems-idps
Topics
Community Discussion
No community discussion yet for this question.