Which statement best describes the action of a Network Intrusion Prevention System (NIPS)?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

Which statement best describes the action of a Network Intrusion Prevention System (NIPS)?

Explanation:
A Network Intrusion Prevention System is intended to sit in-line on the network path so it can enforce security policies in real time by inspecting traffic and blocking malicious activity as it passes. This real-time blocking capability (dropping or resetting offending traffic) is what sets NIPS apart from passive detectors. The other descriptions describe systems that only monitor or log events, or that operate on hosts rather than the network, or that alert without taking action. Therefore, inline traffic control with the ability to block is the best description.

A Network Intrusion Prevention System is intended to sit in-line on the network path so it can enforce security policies in real time by inspecting traffic and blocking malicious activity as it passes. This real-time blocking capability (dropping or resetting offending traffic) is what sets NIPS apart from passive detectors. The other descriptions describe systems that only monitor or log events, or that operate on hosts rather than the network, or that alert without taking action. Therefore, inline traffic control with the ability to block is the best description.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy