Skip to content
ScopefileGet the app

Technique fileSniffing

IDS vs IPS vs firewall: detect, block or filter

An IDS watches traffic or a host and raises an alert, an IPS sits inline and drops what matches, and a firewall permits or denies traffic by rule. The three differ in where they sit and what they are allowed to do about what they see. Network sensors read the same traffic described in the sniffing module; the blueprint covers the devices themselves in Module 12, Evading IDS, Firewalls, and Honeypots.

Exam
312-50
Domain
4 · Network & perimeter
Targets
8

Three devices, side by side

Placement, action and decision basis for each control
TraitIDSIPSFirewall
Placement (differs)Out of band, on a mirror port or tap, or on the hostInline, in the traffic pathInline, at a boundary between zones
Action (differs)Alerts and logs onlyDrops, resets or blocks, and alertsPermits or denies by rule
Decides on (differs)Signatures, anomalies or protocol analysisSignatures, anomalies or protocol analysisAddresses, ports, connection state, and application identity on an NGFW
Cost of a mistake (differs)A missed or noisy alertLegitimate traffic blockedA rule that lets too much through
Host and network forms (differs)HIDS and NIDSHIPS and NIPSHost firewall and network firewall
Needs tuningYesYesYes

Tinted rows marked ≠: at least one of the 3 differs from the others.

Firewall types by what they read

Each generation reads deeper into the traffic
TypeReadsRemembers connectionsWhere it shows up
Packet filterIP and port headersNoRouter access lists, cheap perimeter filtering
Circuit-level gatewaySession setupYes, per sessionChecks that a session is legitimate, never the payload
Stateful inspectionHeaders plus the connection tableYesThe default in most network firewalls
Application proxyFull application contentYesSplits the connection in two and inspects both halves
Next-generation (NGFW)Applications, users, contentYesFirewall with intrusion prevention built in
Web application firewallHTTP requests and responsesYesShields one web app from injection and similar flaws

A web application firewall is grouped with firewalls, but its job is closer to an IPS that speaks only HTTP.

Signature, anomaly, protocol analysis

Signature (misuse) detection compares activity against patterns of known attacks. It is precise on what it knows and needs constant rule updates.

Anomaly detection learns a baseline of normal behavior and flags departures from it, so its quality depends on how good and how current that baseline is.

Stateful protocol analysis checks traffic against how a protocol is supposed to behave, which surfaces odd command sequences and malformed sessions.

Placement matters as much as method. A host-based sensor lives on one machine and sees what that machine does even when the network traffic was encrypted. A network sensor covers a whole segment but only what crosses the wire in readable form. The scan techniques these sensors are built to notice are sorted in the port scan types file.

The four outcomes of an alert

Rows: what really happened. Columns: what the sensor did. The highlighted cell is the dangerous one
Rows: what really happened. Columns: what the sensor did. The highlighted cell is the dangerous oneAlert raisedNo alertAttack happenedTrue positiveFalse negativeNo attackFalse positiveTrue negative

Detect, block or filter?

Some targets ask what a device or detection method is; others describe a network that needs one. Where the device sits is usually the first clue.

Answered 0/8Hits 0

T-01

During a network security audit, this method attempts to recognize breaches based on known attack patterns and misuse signatures. What is this method called?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARule-based detection is a broad description of how many tools work, not the standard name for matching known attack signatures.
  2. BProtocol anomaly detection flags traffic that deviates from protocol specifications, even without a known signature.
  3. CAnomaly detection compares activity to a baseline of normal behavior and can catch unknown attacks, unlike signature matching.
  4. DCorrect: signature recognition, also called misuse detection, matches traffic or events against patterns of known attacks.
T-02

You have implemented a Host-based Intrusion Detection System (HIDS) on your network. How does this help you enhance your security measures and detect potential intrusions?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AScanning applications for SQL injection flaws is the job of web vulnerability scanners and application testing, not a host-based IDS.
  2. BWatching traffic across network segments is what a network-based IDS does, whereas a HIDS focuses on activity on one host.
  3. CCorrect: a HIDS watches activity on the host itself, such as system calls, logs, registry and file integrity changes, to spot intrusions.
  4. DBlocking phishing sites is handled by web filters, secure DNS or proxies, not by a detection system on the host.
T-03

Which type of detection system closely monitors network traffic to identify any patterns indicative of malware or unauthorized activities?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA host-based IDS inspects activity on an individual machine rather than traffic flowing across the network.
  2. BA network-based IPS also inspects traffic but sits inline to block it, whereas the stem describes a system that identifies and alerts.
  3. CA host-based IPS blocks suspicious activity on a single host and does not watch network-wide traffic.
  4. DCorrect: a NIDS passively monitors traffic on a network segment, often via a span port or tap, and alerts on malicious patterns.
T-04

What security mechanism restricts network traffic based on predetermined security rules and connection state information?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA reverse proxy sits in front of servers to forward, cache or balance client requests, not mainly to enforce state-aware filtering rules.
  2. BA forward proxy relays client requests to outside resources and may filter content, but it is not defined by tracking connection state.
  3. CCorrect: a stateful firewall tracks each connection in a state table, allowing return traffic for established sessions and blocking unsolicited packets.
  4. DAn access control list filters on static rules such as addresses and ports, without tracking connection state.
T-05

Which network security device operates at Layer 3 of the OSI model and makes decisions based on source and destination addresses?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AData loss prevention inspects content to stop sensitive data from leaving, not to filter packets by address.
  2. BCorrect: a network firewall acting as a packet filter enforces rules on source and destination IP addresses at the network layer.
  3. CA web application firewall works at Layer 7, inspecting HTTP requests for attacks like SQL injection and XSS.
  4. DAn IPS inspects traffic content and behavior against signatures and anomalies, beyond simple address-based rules.
T-06

What does it signify when a firewall experiences a false positive?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMissing a real attack is a false negative, which is usually the more dangerous error.
  2. BCorrect: a false positive is an alert or block triggered by legitimate activity that the system wrongly treats as malicious.
  3. CSpotting and stopping a real attack is a true positive, which is the outcome detection systems are tuned to achieve.
  4. DNo false alerts describes the absence of false positives, which rule tuning aims for but rarely fully achieves.
T-07

A security team wants a device placed directly in the traffic path that inspects each packet and discards any packet matching a known attack before it reaches the server. An out-of-band sensor that only raises an alert is not acceptable. Which device meets this requirement?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA network IDS usually watches a copy of traffic out of band and alerts; it does not sit inline to drop the malicious packet itself.
  2. BA honeypot is a decoy that attracts and records attackers; it does not inspect or block traffic headed to the real production server.
  3. CCorrect: an IPS sits inline in the traffic path, so it can inspect each packet and drop a malicious one before it reaches its target.
  4. DA caching forward proxy relays and stores client web requests for performance; it is not an attack-detection device that drops malicious packets to servers.
T-08

A SOC manager notes that the current IDS missed a brand-new exploit because no rule for it existed yet. The team wants detection that can flag attacks never seen before. Which approach fits, and what is its usual trade-off?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: anomaly-based detection compares activity with a learned baseline, so it can flag novel attacks, but normal deviations often trigger false positives.
  2. BSignature-based detection only matches known patterns, so even frequent updates cannot catch an attack that has no rule written yet.
  3. CBeing good at known attacks does not solve the problem; a signature engine still cannot recognize an exploit no one has described.
  4. DAnomaly detection relies on a behavioral baseline, not on signatures, so this stated limitation is false and the trade-off is wrong.

Follow-up questions

Where do honeypots fit next to these three?

A honeypot is a decoy with no production purpose, so any interaction with it is suspicious by definition. Low-interaction honeypots emulate a few services; high-interaction ones run real systems and collect far more, at more risk.

Is an NGFW just an IPS with a firewall bolted on?

Close enough for study purposes. Its defining additions are application awareness, user identity and an integrated intrusion prevention engine, all in one inline device.

How big is this topic on the blueprint?

Module 12 sits in Domain 4, Network and Perimeter Hacking, which blueprint v5.0 weights at 24% of the exam (checked Oct 11, 2026). That share is spread over five modules.

Sources