nerdexam
HP

HPE7-A02 · Question #135

A company has been running Gateway IDS/IPS on its gateways in IDS mode for several weeks. The company wants to transition to IPS mode. What is one step you should recommend?

The correct answer is D. Check for legitimate traffic that has been flagged as a threat and allow list the associated rules. When transitioning from Intrusion Detection System (IDS) mode to Intrusion Prevention System (IPS) mode, it's critical to review and refine configurations to ensure legitimate traffic is not In IDS mode, the system only detects and logs suspicious traffic but does not block it…

Implementing Advanced Security Features

Question

A company has been running Gateway IDS/IPS on its gateways in IDS mode for several weeks. The company wants to transition to IPS mode. What is one step you should recommend?

Options

  • ADisable traffic inspection and reboot before re-enabling traffic inspection with the new mode.
  • BChange the mode on one gateway at a time to establish a smoother transition period.
  • CConsider applying a stricter IPS policy to minimize issues during the transition period.
  • DCheck for legitimate traffic that has been flagged as a threat and allow list the associated rules.

How the community answered

(41 responses)
  • A
    12% (5)
  • B
    22% (9)
  • C
    5% (2)
  • D
    61% (25)

Explanation

When transitioning from Intrusion Detection System (IDS) mode to Intrusion Prevention System (IPS) mode, it's critical to review and refine configurations to ensure legitimate traffic is not In IDS mode, the system only detects and logs suspicious traffic but does not block it. Reviewing these logs for false positives allows the organization to fine-tune policies and allow list legitimate traffic before transitioning to IPS mode. By doing this, the company ensures that IPS mode will block actual threats while permitting legitimate traffic. This is a proactive step to prevent unnecessary disruptions to normal operations when IPS mode

Topics

#IDS/IPS#IPS mode transition#rule allowlisting#gateway security

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice