Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security
Network Security Tools and Controls: Firewalls, IDS, IPS and VPN
Updated 11 October 2026 · Fact-checked
Network security tools and controls are the devices, software and rules that protect a network from unauthorised access and attack. Firewalls filter traffic, IDS detects and alerts, IPS detects and blocks, VPNs encrypt traffic over public links, antivirus removes malware, proxies mediate requests, and access controls limit who can do what.
Understand Network Security Tools and Controls
A network carries data between computers. Anyone who can reach the network can try to read, change or block that data. Network security tools reduce that risk. No single tool is enough, so organisations stack several. This is called defence in depth.
A firewall sits between networks, usually your internal network and the internet, and allows or blocks traffic using rules. A packet filtering firewall checks each packet's source and destination address, port and protocol. A stateful inspection firewall also tracks the state of each connection, so it allows replies only to requests that started inside. A proxy (application) firewall works at the application level and inspects the content of the request. A next-generation firewall (NGFW) adds deeper inspection, application awareness and built-in intrusion prevention.
An intrusion detection system (IDS) watches traffic or hosts and raises an alert on suspicious activity. It does not stop the traffic itself. An intrusion prevention system (IPS) sits in the path of traffic and can drop the packet, block the source or reset the connection. Both detect using signatures (known attack patterns) or anomaly detection (deviation from normal behaviour). Anomaly detection can catch new attacks but gives more false alarms. Network-based systems (NIDS/NIPS) watch the network. Host-based systems (HIDS/HIPS) watch one machine.
A VPN (virtual private network) creates an encrypted tunnel across a public network such as the internet. A staff member working from home connects to the company network as if on site, and outsiders cannot read the traffic. A proxy server is an intermediary: users send requests to it and it fetches the content for them. It can hide internal addresses, filter websites, log use and cache content. Antivirus software scans files and processes for malware by signature, behaviour or heuristics, and needs regular updates.
Access controls decide who may use which resource. They rest on authentication (proving identity, ideally with multi-factor authentication), authorisation (what that identity may do) and accounting (recording what it did). Common models are role-based access control and the principle of least privilege, meaning each user gets only the access the job needs.
Key rules to remember
- Firewall vs IDS vs IPS
- Firewall = filter by rules; IDS = detect + alert; IPS = detect + block
- IDS is passive and out of the traffic path. IPS is active and inline.
- Types of firewall
- Packet filter → Stateful inspection → Proxy/application → NGFW
- Inspection gets deeper at each stage, with more processing cost.
- Detection methods
- Signature-based (known attacks) | Anomaly-based (unusual behaviour)
- Signature misses new attacks. Anomaly gives more false positives.
- Access control (AAA)
- Authentication → Authorisation → Accounting
- Who are you, what can you do, what did you do.
- Least privilege
- Access granted = minimum needed for the role
- Reduces damage from errors, misuse and compromised accounts.
- VPN purpose
- Public network + encryption tunnel = private communication
- Gives confidentiality and integrity of data in transit. It does not remove malware.
How to solve Network Security Tools and Controls questions
Most questions ask you to explain a tool, compare two tools, or recommend controls for a scenario. Use this order.
- 1Read the verb: define, differentiate, explain or advise. It sets the answer's shape.
- 2Define each tool in one line, saying what it protects and where it sits in the network.
- 3Explain how it works in two or three points, such as rules, signatures or encryption tunnel.
- 4For a comparison, use clear points: purpose, action taken, position in traffic, and limitation.
- 5For a scenario, list the risks in the facts, then match one tool or control to each risk.
- 6Add layering: say no single control is enough and mention defence in depth.
- 7Add practical points: updates, logs, review of rules, staff training and policy.
- 8Close with a one-line conclusion tied to the facts given.
Quickest way: Risk-to-tool matching
When to use it: Use it for scenario questions when time is short.
- Underline each risk in the facts: outsider access, remote staff, malware, unknown attack, excess user rights.
- Write the matching tool beside each: firewall, VPN, antivirus, IPS or IDS, access control.
- Give one line on how each tool works.
- Add one line on layered security and regular updates and review.
- Finish with a conclusion.
Common mistakes in Network Security Tools and Controls
Saying an IDS blocks attacks.
The names IDS and IPS sound alike and both detect.
Fix: Remember D is for detect and alert only. P is for prevent, which means block.
Treating a firewall as protection against everything.
Students see it as the main network defence.
Fix: State its limits: it cannot stop threats from inside, malware that arrives through allowed traffic, or social engineering.
Claiming a VPN makes a user safe from malware.
Encryption is confused with protection from malicious files.
Fix: Say a VPN protects data in transit. Antivirus and endpoint controls are still needed.
Mixing a proxy server with a VPN.
Both hide the user's address.
Fix: A proxy relays requests for specific applications and filters or caches. A VPN encrypts all traffic through a tunnel.
Listing tools with no link to the facts.
Students recall notes instead of analysing the case.
Fix: Tie each tool to a stated risk and give a reason for choosing it.
Forgetting authentication and least privilege in access control answers.
Access control is reduced to passwords.
Fix: Cover identity proof, multi-factor authentication, role-based rights and logging.
Worked examples
Example 1
Differentiate between an intrusion detection system and an intrusion prevention system.
Show the solution
- Define IDS: it monitors traffic or hosts and alerts administrators on suspicious activity.
- Define IPS: it monitors traffic and automatically acts, such as dropping packets or blocking the source.
- Position: IDS is usually passive and works on a copy of traffic. IPS is placed inline in the traffic path.
- Action: IDS only reports, so a person must respond. IPS responds at once.
- Risk: a faulty IDS misses alerts but does not stop business traffic. A faulty IPS may block genuine traffic through false positives.
- Common ground: both use signature-based or anomaly-based detection.
Answer: An IDS detects and alerts and is passive. An IPS detects and blocks and is inline. Organisations often use both, with IPS to stop known attacks and IDS for visibility and investigation.
Example 2
A Pune manufacturing company lets 40 employees work from home. Staff reach the company server over the internet, some have downloaded files from unknown sites, and all users currently have administrator rights. Advise on suitable network security controls.
Show the solution
- Risk 1, remote access over the internet: data in transit can be intercepted. Recommend a VPN so traffic travels in an encrypted tunnel, with multi-factor authentication.
- Risk 2, outsiders reaching the server: place a firewall at the network edge with rules allowing only required ports and services.
- Risk 3, downloads from unknown sites: install antivirus on all devices with automatic updates, and use a proxy server to filter unsafe websites and log use.
- Risk 4, attacks that pass the firewall: deploy an IPS to block known attack patterns and keep an IDS or logging for alerts.
- Risk 5, administrator rights for all: apply least privilege and role-based access, so staff get only the rights needed. Review rights regularly.
- Add practice: written security policy, staff awareness training, log review and periodic rule review.
- Conclusion: layered controls give defence in depth because no single tool covers all the risks.
Answer: Use a VPN with multi-factor authentication for remote access, a firewall at the edge, antivirus and a proxy for downloads, an IPS and IDS for attacks, and least privilege access, supported by policy, training and regular review.
Exam tips
- Differentiation questions are common. Use a point-by-point layout, with at least three points.
- In scenario answers, name the risk first and the tool second. Examiners reward the link.
- Always mention limitations of a tool. It shows analysis and separates your answer from a list.
- End with defence in depth and the need for updates, monitoring and policy.
- Use correct terms: stateful inspection, signature-based, anomaly-based, least privilege and multi-factor authentication.
Practice questions from Network Basics and Security
- A company allows staff to log in to its network only after entering a password and then a one-time code sent to their registered mobile phon…
- Mehta Textiles Ltd. uses a firewall that filters traffic purely on source and destination IP addresses. At which OSI layer does this filteri…
- A company secretary of a Mumbai firm wants to send a confidential board resolution draft to a director so that only the director can read it…
- A Mumbai-based fintech firm wants an independent certificate that its information security management system meets an international benchmar…
- A Mumbai firm finds that an attacker, after gaining access without authority, copied customer data from its network and deleted logs. Which …
Network Security Tools and Controls: frequently asked questions
How does a firewall work?
A firewall compares each packet or connection with a set of rules covering addresses, ports, protocols or applications. It allows traffic that matches an allow rule and blocks the rest. Stateful firewalls also track connections, and next-generation firewalls inspect application content.
What are the types of firewalls?
The main types are packet filtering, stateful inspection, proxy or application-level, and next-generation firewalls. Firewalls may also be described as network-based or host-based. Know one line of function and one limitation for each.
What is the difference between IDS and IPS?
An IDS detects suspicious activity and alerts people. An IPS sits inline and blocks the activity automatically. IPS acts faster but can block genuine traffic if it raises a false positive.
What is a VPN and how does it work?
A VPN creates an encrypted tunnel between a user's device and a network over the internet. Data inside is unreadable to outsiders. It protects data in transit but does not remove malware from the device.