header bg

Scan QR code or get instant email to install app

Question:

Emily manages the IDS/IPS for her network. She has a network-based intrusion prevention system (NIPS) installed and properly configured. It does not detect obvious attacks on one specific network segment. She has verified that the NIPS is properly configured and working properly. What would be the MOST efficient way for her to address this?

A Implement port mirroring for that segment.
explanation

The NIPS is not seeing the traffic on that network segment. By implementing port mirroring, the traffic from that segment can be copied to the segment where the NIPS is installed. Installing a network IPS on the segment would require additional resources. This would work but is not the most efficient approach. Nothing in this scenario suggests that the NIPS is inadequate. It just is not seeing all the traffic. Finally, isolating the segment to its own VLAN would isolate that network segment but would still not allow the NIPS to analyze the traffic from that segment.

Related Information

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

*