nerdexam
GIAC

GSLC · Question #362

Which system is designed to analyze, detect, and report on security-related events?

The correct answer is B. NIPS. NIPS monitors network traffic to analyze, detect, and report on security events, operating inline across the network.

Security Operations & Incident Response Leadership

Question

Which system is designed to analyze, detect, and report on security-related events?

Options

  • AHIPS
  • BNIPS
  • CNIDS
  • DHIDS

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    90% (19)
  • C
    5% (1)

Why each option

NIPS monitors network traffic to analyze, detect, and report on security events, operating inline across the network.

AHIPS

HIPS (Host-based Intrusion Prevention System) operates on a single host rather than monitoring network-wide traffic, so it cannot report on events across the broader network.

BNIPSCorrect

NIPS (Network Intrusion Prevention System) is deployed inline on the network and is designed to monitor, analyze, and report on security-related events across network traffic in real time. It inspects packets flowing through the network segment and generates alerts and reports on detected threats. Its network-wide scope makes it the appropriate system for broad security event analysis and reporting across multiple hosts.

CNIDS

NIDS (Network Intrusion Detection System) is a passive system that only detects and reports without taking preventive action, making it a subset of what NIPS offers.

DHIDS

HIDS (Host-based Intrusion Detection System) monitors activity only on the individual host where it is installed, not across the network.

Concept tested: Network intrusion prevention system roles and capabilities

Source: https://www.nist.gov/publications/guide-intrusion-detection-and-prevention-systems-idps

Topics

#NIPS#NIDS#intrusion detection#security monitoring

Community Discussion

No community discussion yet for this question.

Full GSLC Practice