An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?
Choose an answer
Tap an option to check your answer.
Correct answer: IPS.
Why this is the answer
An Intrusion Prevention System (IPS) is the best solution because it actively monitors network traffic for known attack signatures and can block malicious activity in real-time. This directly addresses the problem of exploiting vulnerabilities with well-known exploits. An Intrusion Detection System (IDS) can detect these attacks but only alerts administrators; it does not block them. An Access Control List (ACL) filters traffic based on rules like IP addresses or ports, but it cannot detect and block signature-based attacks. Data Loss Prevention (DLP) focuses on preventing sensitive data from leaving the organization and is not designed to stop exploit-based attacks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed