Which security solution monitors and blocks known signature-based attacks?

Network Security

An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?

  1. ACL
  2. DLP
  3. IDS
  4. IPS Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between detection-only systems (IDS) and prevention systems (IPS), with the trap being the confusion between 'monitoring' and 'blocking' capabilities.

An Intrusion Prevention System (IPS) is the optimal choice for actively monitoring network traffic and blocking known signature-based exploits. Community consensus confirms IPS over IDS because only IPS can automatically block threats in real-time.

Candidates often select C (IDS) because it detects attacks, but fail to notice the requirement to 'block' them, which IDS cannot do natively without external integration.

Community Discussion (14 comments)

AutoroTink 👍 16 Selected: D
An IPS is designed to continuously monitor network traffic and take immediate action to block potential threats based on known signatures. It’s an active security measure that not only detects but also prevents the exploitation of known vulnerabilities. A. ACL (Access Control List): ACLs are used to control the flow of traffic based on rules, but they are not dynamic enough to monitor or block signature-based attacks effectively. B. DLP (Data Loss Prevention): DLP systems are focused on preventing data breaches by detecting and blocking potential data leaks/exfiltration, not on monitoring or blocking attacks per se. C. IDS (Intrusion Detection System): While an IDS can detect known signature-based attacks, it does not block them; it only alerts the system administrators of the potential threat. D. IPS (Intrusion Prevention System): As mentioned, an IPS actively monitors and blocks attacks, making it the most suitable option for the scenario described.
barracouto 👍 5 Selected: D
ACL (Access Control List): Used to control network traffic and define which users or system processes have permissions to access resources or perform operations on a network. DLP (Data Loss Prevention): Designed to prevent sensitive data from being lost, misused, or accessed by unauthorized users, and to monitor data transfers to ensure compliance with data protection policies. IDS (Intrusion Detection System): Monitors network or system activities for malicious activities or policy violations. An IDS alerts administrators of potential threats but does not take action to block them. IPS (Intrusion Prevention System): Monitors and controls network and system activities to protect against malicious activities by detecting and preventing attacks in real-time. An IPS can block traffic that matches known attack signatures. Correct Answer: D. IPS The IPS is the appropriate solution as it can monitor and block known signature-based attacks.
Collapsar 👍 1 Selected: D
An IPS is designed to continuously monitor network traffic and take immediate action to block potential threats based on known signatures. It’s an active security measure that not only detects but also prevents the exploitation of known vulnerabilities. A. ACL (Access Control List): ACLs are used to control the flow of traffic based on rules, but they are not dynamic enough to monitor or block signature-based attacks effectively. B. DLP (Data Loss Prevention): DLP systems are focused on preventing data breaches by detecting and blocking potential data leaks/exfiltration, not on monitoring or blocking attacks per se. C. IDS (Intrusion Detection System): While an IDS can detect known signature-based attacks, it does not block them; it only alerts the system administrators of the potential threat. D. IPS (Intrusion Prevention System): As mentioned, an IPS actively monitors and blocks attacks, making it the most suitable option for the scenario described.
bufffalobilll 👍 1 Selected: D
And block
a0bfa81 👍 1 Selected: D
D. IPS - Intrusion Prevention System is the correct answer
93a09c9 👍 1
D is the correct answer here. The answer is most definitely not C.
Etc_Shadow28000 👍 1 Selected: D
D. IPS (Intrusion Prevention System) An Intrusion Prevention System (IPS) is designed to monitor network and/or system activities for malicious activities or policy violations and can take actions to block or prevent those activities. Since the enterprise is dealing with known signature-based attacks, an IPS is the best solution because it can actively block these attacks by using signatures to identify and mitigate them in real-time. Therefore, the correct answer is: D. IPS
Shaman73 👍 1 Selected: D
D: IPS
SHADTECH123 👍 3 Selected: D
An Intrusion Prevention System (IPS) is designed to monitor network traffic for suspicious activity, and it can take proactive steps to block or prevent those activities in real-time. IPS uses signature-based detection to identify known vulnerabilities and exploits, making it particularly effective against attacks that exploit well-documented and widely known browser vulnerabilities.
shady23 👍 1 Selected: D
D. IPS
Mehsotopes 👍 1 Selected: C
An IPS system being configured can have a chance of blocking code that certain systems with newer web browsers may need, or not be vulnerable to at all. An IDS would allow you to be notified of these recognized signatures, & determine if it's appropriate to allow, or not. Another safe option would be to know what systems are using older browser versions, & update them, if not, then segment them specifically, & use an IPS appliance if anti-virus automation is what is necessary.
e5c1bb5 👍 1 Selected: D
was confused by "correct answer" IPS forsure
Kevans242 👍 1 Selected: D
Definitely D
e56400d 👍 2
Can someone explain to me why the answer is IDS? IDS only alerts, it does not block anything. IPS alerts and blocks suspicious activity. Therefore, the answer should be IPS.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An Intrusion Prevention System (IPS) sits inline with network traffic and uses signature-based detection to identify known vulnerabilities and exploits. Unlike passive monitoring tools, an IPS is designed to take immediate, active action to block or prevent malicious packets from reaching their destination. This aligns perfectly with the requirement to both monitor and block known signature-based attacks against older browser versions.

Why the Other Options Are Wrong

Access Control Lists (ACL) filter traffic based on IP addresses and ports but lack deep packet inspection for specific exploit signatures. Data Loss Prevention (DLP) focuses on protecting sensitive data from exfiltration rather than blocking network-level exploits. An Intrusion Detection System (IDS) only alerts administrators to suspicious activity; it does not have the capability to actively drop packets or block connections in real-time, making it insufficient for the 'block' requirement.

Community Comment Notes

Comment [1] highlights that ACLs are not dynamic enough for signature-based monitoring. Comment [3] emphasizes that IPS is particularly effective against well-documented browser vulnerabilities due to its proactive blocking nature. Comment [9] raises a valid concern about false positives with IPS, suggesting segmentation as an alternative, but notes that for the exam's specific wording, IPS is the intended answer. Comment [4] correctly identifies the core differentiator: IDS alerts, while IPS blocks.

Exam Strategy

Always look for keywords like 'block', 'prevent', or 'stop' when choosing between IDS and IPS; these indicate the need for an active response system. If the scenario requires only 'detecting' or 'alerting', choose IDS. For SY0-701, remember that IPS is the standard solution for automated threat mitigation.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide