New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 10 Question 18 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 18
Topic #: 10
[All CSSLP Questions]

Which of the following statements about a host-based intrusion prevention system (HIPS) are true?

Each correct answer represents a complete solution. Choose two.

Show Suggested Answer Hide Answer
Suggested Answer: C, D

A host-based intrusion prevention system (HIPS) is an application usually employed on a single computer. It complements traditional finger-

print-based and heuristic antivirus detection methods, since it does not need continuous updates to stay ahead of new malware. When a

malicious code needs to modify the system or other software residing on the machine, a HIPS system will notice some of the resulting changes

and prevent the action by default or notify the user for permission. It can handle encrypted and unencrypted traffic equally and cannot detect

events scattered over the network.

Answer B is incorrect. Network address translation (NAT) is a technique that allows multiple computers to share one or more IP

addresses. NAT is configured at the server between a private network and the Internet. It allows the computers in a private network to share

a global, ISP assigned address. NAT modifies the headers of packets traversing the server. For packets outbound to the Internet, it translates

the source addresses from private to public, whereas for packets inbound from the Internet, it translates the destination addresses from

public to private.

Answer A is incorrect. Network intrusion prevention system (NIPS) is a hardware/software platform that is designed to analyze, detect,

and report on security related events. NIPS is designed to inspect traffic and based on its configuration or security policy, it can drop malicious

traffic. NIPS is able to detect events scattered over the network and can react.


Contribute your Thoughts:

0/2000 characters
Elbert
4 months ago
Wait, it can't detect network events? That's surprising!
upvoted 0 times
...
Ira
4 months ago
A is misleading, HIPS is host-based, not network-based.
upvoted 0 times
...
Brunilda
4 months ago
C sounds a bit off to me, how can it handle encrypted traffic?
upvoted 0 times
...
Horace
4 months ago
Totally agree, D is definitely true!
upvoted 0 times
...
Carmelina
5 months ago
HIPS can't detect network-wide events, that's a fact.
upvoted 0 times
...
Margot
5 months ago
I feel like HIPS is more about local detection rather than network-wide, so D seems right. But I’m not confident about C.
upvoted 0 times
...
Dominga
5 months ago
I practiced a question similar to this, and I recall that HIPS is not about sharing IP addresses, so B should definitely be wrong.
upvoted 0 times
...
Carissa
5 months ago
I’m not entirely sure, but I think HIPS can handle encrypted traffic since it monitors the host. Maybe C is correct too?
upvoted 0 times
...
Agustin
5 months ago
I remember HIPS is focused on the host itself, so I think it can't really detect events across the network. That makes me lean towards option D.
upvoted 0 times
...
Bette
5 months ago
Tanzu Kubernetes Grid sounds like the best fit based on the question, but I'll double-check the other options just to be sure.
upvoted 0 times
...
Maddie
5 months ago
This looks like a pretty straightforward file management task, but I want to make sure I get all the details right. I'll need to copy the file, set the ownership and permissions, and create the new user.
upvoted 0 times
...

Save Cancel