Which of the following is an automatic system that detects intrusions and can take actions to prevent them, typically deployed behind firewalls?

Prepare for the Certified Ethical Hacker Version 11 Exam. Study with comprehensive questions and explanations. Equip yourself with the skills needed for success!

Multiple Choice

Which of the following is an automatic system that detects intrusions and can take actions to prevent them, typically deployed behind firewalls?

Explanation:
An Intrusion Prevention System fits this description. It’s deployed in line with network traffic and can not only detect signs of intrusion but also automatically stop them in real time—dropping malicious packets, resetting connections, or applying rate limiting as needed. This inline, active prevention is what sets it apart from an IDS, which only detects and alerts without blocking traffic on its own. Firewalls control access based on rules but don’t usually inspect payloads for intrusions, while a DMZ is simply a network zone, not a protective system. Placing an IPS behind the firewall adds a proactive layer that can respond to threats the firewall might not catch.

An Intrusion Prevention System fits this description. It’s deployed in line with network traffic and can not only detect signs of intrusion but also automatically stop them in real time—dropping malicious packets, resetting connections, or applying rate limiting as needed. This inline, active prevention is what sets it apart from an IDS, which only detects and alerts without blocking traffic on its own. Firewalls control access based on rules but don’t usually inspect payloads for intrusions, while a DMZ is simply a network zone, not a protective system. Placing an IPS behind the firewall adds a proactive layer that can respond to threats the firewall might not catch.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy