Which security solution monitors and blocks known signature-based attacks?
An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between detection-only systems (IDS) and prevention systems (IPS), with the trap being the confusion between 'monitoring' and 'blocking' capabilities.
An Intrusion Prevention System (IPS) is the optimal choice for actively monitoring network traffic and blocking known signature-based exploits. Community consensus confirms IPS over IDS because only IPS can automatically block threats in real-time.
Candidates often select C (IDS) because it detects attacks, but fail to notice the requirement to 'block' them, which IDS cannot do natively without external integration.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An Intrusion Prevention System (IPS) sits inline with network traffic and uses signature-based detection to identify known vulnerabilities and exploits. Unlike passive monitoring tools, an IPS is designed to take immediate, active action to block or prevent malicious packets from reaching their destination. This aligns perfectly with the requirement to both monitor and block known signature-based attacks against older browser versions.Why the Other Options Are Wrong
Access Control Lists (ACL) filter traffic based on IP addresses and ports but lack deep packet inspection for specific exploit signatures. Data Loss Prevention (DLP) focuses on protecting sensitive data from exfiltration rather than blocking network-level exploits. An Intrusion Detection System (IDS) only alerts administrators to suspicious activity; it does not have the capability to actively drop packets or block connections in real-time, making it insufficient for the 'block' requirement.Community Comment Notes
Comment [1] highlights that ACLs are not dynamic enough for signature-based monitoring. Comment [3] emphasizes that IPS is particularly effective against well-documented browser vulnerabilities due to its proactive blocking nature. Comment [9] raises a valid concern about false positives with IPS, suggesting segmentation as an alternative, but notes that for the exam's specific wording, IPS is the intended answer. Comment [4] correctly identifies the core differentiator: IDS alerts, while IPS blocks.Exam Strategy
Always look for keywords like 'block', 'prevent', or 'stop' when choosing between IDS and IPS; these indicate the need for an active response system. If the scenario requires only 'detecting' or 'alerting', choose IDS. For SY0-701, remember that IPS is the standard solution for automated threat mitigation.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →