ExamGecko
Question list
Search
Search

Question 75 - ICS-SCADA Cyber Security discussion

Report
Export

Which type of Intrusion Prevention System can monitor and validate encrypted data?

A.
Memory
Answers
A.
Memory
B.
Network
Answers
B.
Network
C.
Host
Answers
C.
Host
D.
Anomaly
Answers
D.
Anomaly
Suggested answer: B

Explanation:

A Network Intrusion Prevention System (NIPS) is capable of monitoring and validating encrypted data if it is integrated with technologies that allow it to decrypt the traffic.

Typically, network IPS can be set up with SSL/TLS decryption capabilities to inspect encrypted data as it traverses the network. This allows the IPS to analyze the content of encrypted packets and apply security policies accordingly.

Monitoring encrypted traffic is critical in detecting hidden malware, unauthorized data exfiltration, and other security threats concealed within SSL/TLS encrypted sessions.

Reference

'Network Security Technologies and Solutions,' by Yusuf Bhaiji, Cisco Press.

'Decrypting SSL/TLS Traffic with IPS,' by Palo Alto Networks.

asked 18/09/2024
Alejandro Meza
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first