200-201 exam dumps

200-201 practice question 229 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 229

Single answer

You are a cybersecurity analyst monitoring network traffic in your organization. Your Intrusion Detection System (IDS) generates an alert indicating a potential SQL injection attack targeting a web application. Upon further investigation, you find that the attack was successfully blocked before reaching the application server. Which of the following statements best describes the role of the security solution in this scenario?

  1. A

    The IDS detected and blocked the SQL injection attack before it reached the application server.

  2. B

    The IDS detected the SQL injection attack and generated an alert, while an Intrusion Prevention System (IPS) blocked the attack.

  3. C

    The IDS failed to identify the attack, and the application server's firewall blocked the SQL injection attack.

  4. D

    The IDS operates as an inline device and actively stopped the SQL injection attack.

Show answer and explanation

Correct answer: B

Explanation

An Intrusion Detection System (IDS) passively monitors network traffic and raises alerts when suspicious activity is detected. However, it does not have the capability to block threats. In this scenario, an Intrusion Prevention System (IPS) worked in conjunction with the IDS, actively blocking the SQL injection attack. This highlights the complementary roles of IDS and IPS in a layered security architecture.

  • A. Incorrect.

    Incorrect. An IDS is a passive monitoring solution that generates alerts but does not block attacks. Blocking requires an IPS or other active security mechanism.

  • B. Correct.

    Correct. This scenario describes the combined functionality of an IDS and IPS. The IDS detected the attack and generated the alert, while the IPS actively blocked the malicious traffic.

  • C. Incorrect.

    Incorrect. The scenario specifically states the IDS generated an alert, meaning it successfully detected the attack. The application server's firewall is not mentioned as part of the blocking mechanism.

  • D. Incorrect.

    Incorrect. An IDS is not an inline device; it passively monitors traffic and generates alerts. Active blocking is performed by an IPS.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam