A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?
Choose an answer
Tap an option to check your answer.
Correct answer: Intrusion prevention systems.
Why this is the answer
Intrusion Prevention Systems (IPS) are the most secure method because they actively monitor network traffic for malicious activity and can automatically block or drop packets that match known attack signatures or anomalous behavior. This proactive approach prevents malicious packets from reaching internal systems. Anti-malware solutions primarily protect endpoints from malware after it has bypassed network defenses, not specifically against malicious network packets. Host-based firewalls protect individual hosts but don't offer centralized network-wide protection against external threats. Network access control (NAC) manages device authentication and authorization to the network but doesn't inspect packet content for malicious intent. Network allow lists (whitelisting) restrict traffic to only explicitly permitted sources or destinations, which is a good security practice but less dynamic in detecting and preventing novel or evolving malicious packet attacks compared to an IPS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed