An unknown source has attacked an organization's network multiple times. The organization has a firewall but no other source of protection against these attacks. Which of the following is the best security item to add?
IPS
Adding an Intrusion Prevention System (IPS) would be the most effective security measure in this scenario. Unlike a firewall that primarily focuses on traffic filtering based on predetermined security rules, an IPS actively monitors network traffic for malicious activities and can block potential threats in real-time.
A Security Information and Event Management (SIEM) system is valuable for collecting, analyzing, and correlating security events from various sources. However, in a situation where immediate protection against ongoing attacks is crucial, an IPS would be more suitable as it actively prevents and detects intrusions.
A load balancer distributes incoming network traffic across multiple servers to ensure efficient resource utilization and prevent server overload. While it is essential for optimizing server performance and availability, a load balancer does not offer the security functionalities needed to counteract repeated attacks.
Unified Threat Management (UTM) devices combine multiple security features such as firewall, antivirus, intrusion detection, and content filtering into a single appliance. While UTM solutions provide comprehensive protection, an intrusion prevention system like IPS specifically focuses on identifying and blocking malicious activities in real-time.
An Intrusion Prevention System (IPS) actively monitors network traffic patterns, detects potential security threats, and takes immediate action to block or prevent unauthorized access. By adding an IPS to the existing security infrastructure, the organization can enhance its defense mechanisms against the persistent attacks, mitigating risks effectively.
Given the repeated attacks on the organization's network and the existing reliance solely on a firewall for protection, the most suitable security item to add would be an Intrusion Prevention System (IPS). This proactive security measure can help in identifying and thwarting malicious activities in real-time, strengthening the overall security posture of the organization against persistent threats.
Related Questions
View allA security analyst must prevent remote users from accessing malicious...
Which of the following best explains a concern with OS-based vulnerabi...
A network administrator wants to ensure that network traffic is highly...
Which of the following hardening techniques must be applied on a conta...
A business is expanding to a new country and must protect customers fr...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations