Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

The security team of Bharat Textiles Ltd. deploys a system that monitors network traffic, compares it with known attack signatures and automatically drops packets that match an attack pattern before they reach the server. Which description is most accurate for this system?

It is an Intrusion Prevention System. An IPS sits inline with traffic, matches it against attack signatures and actively drops malicious packets. An Intrusion Detection System merely monitors and alerts without blocking, so it does not fit a system that automatically stops the attack.

  1. AIntrusion Detection System, because it only raises alerts and cannot block traffic
  2. BIntrusion Prevention System, because it sits inline and can actively block malicious trafficCorrect
  3. CVirtual Private Network, because it encrypts traffic between sites
  4. DHoneypot, because it lures attackers into a decoy system

Explanation

An IPS operates inline and takes action, such as dropping packets, on detecting malicious patterns. An IDS is passive and only alerts, so the first option is wrong because the system here blocks traffic. A VPN encrypts and a honeypot is a decoy; neither matches the described behaviour.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions