medium
Single Answer
0Neil wants to deploy a host-intrusion prevention system that will use a third-party threat feed to servers in his datacenter. What concern might his system administrators express about the HIPS that he should consider before he makes the decision?
Answer Options
A
A HIPS may block traffic, causing an outage or disruption.
B
A HIPS may prevent least privilege configurations.
C
A HIPS may bypass application allow lists.
D
A HIPS may make use of segmentation less effective.
Correct Answer: A
Explanation
A HIPS may block legitimate traffic if the traffic matches an existing rule or if a threat feed is used and has a detection that matches that traffic. That means that organizations that deploy HIPS in datacenters where disruptions could cause significant outages are careful about what rules they put in place and how threat feed data is used. A HIPS doesn't prevent least privilege and typically doesn't interact with application allow lists, and segmentation should not impact a HIPS.