ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 324 - SY0-701 discussion

Report
Export

A security engineer is installing an IPS to block signature-based attacks in the environment. Which of the following modes will best accomplish this task?

A.
Monitor
Answers
A.
Monitor
B.
Sensor
Answers
B.
Sensor
C.
Audit
Answers
C.
Audit
D.
Active
Answers
D.
Active
Suggested answer: D

Explanation:

To block signature-based attacks, the Intrusion Prevention System (IPS) must be in active mode. In this mode, the IPS can actively monitor and block malicious traffic in real time based on predefined signatures. This is the best mode to prevent known attack types from reaching the internal network.

Monitor mode and sensor mode are typically passive, meaning they only observe and log traffic without actively blocking it.

Audit mode is used for review purposes and does not actively block traffic.

asked 02/10/2024
Phil Horikawa
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first