A company's network is experiencing high levels of suspicious network traffic. The security team finds that the traffic is coming from an unknown, foreign IP address. Which of the following is the most cost-efficient way to mitigate this threat?
Implementing an Access Control List (ACL) is the most cost-efficient way to mitigate the threat.
An Access Control List (ACL) allows a security team to define which IP addresses can access the network, effectively blocking unwanted or suspicious traffic from unknown sources. This method is typically low-cost and can be implemented quickly on routers or firewalls.
ACLs provide a straightforward and cost-effective way to filter network traffic based on IP addresses. By configuring an ACL to block the suspicious foreign IP address, the security team can effectively mitigate the threat without incurring additional costs associated with more complex security measures.
An Intrusion Detection System (IDS) monitors network traffic for suspicious activity but does not actively prevent it. While useful for identifying threats, implementing an IDS can be costly and may not provide immediate mitigation against the current threat posed by the foreign IP address.
Network Address Translation (NAT) is primarily used for mapping private IP addresses to a public IP address and is not designed for traffic filtering based on IP reputation. While it helps in hiding internal IP addresses, it does not mitigate threats from suspicious traffic directly and does not provide a cost-effective solution for addressing the immediate concern.
Denial of Service (DoS) prevention methods focus on mitigating attacks aimed at overwhelming the network, rather than blocking specific suspicious traffic. While essential for network security, these solutions can be complex and costly, making them less suitable for addressing the specific issue of unauthorized access from a foreign IP.
Mitigating threats from suspicious network traffic is crucial for maintaining security, and using an ACL offers a practical and cost-efficient solution. By blocking specific IP addresses, organizations can quickly respond to threats without incurring high expenses, unlike more complex systems that may not address the immediate risks effectively.
Related Questions
View allA network administrator needs to stabilize connectivity between two bu...
Which of the following is the best way to securely access a network ap...
A company security policy requires all network traffic from remote emp...
A network engineer configures network ports in a public office. To inc...
A network administrator is establishing Layer 3 connectivity between L...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations