1.2 Implement NGIPS modes Flashcards

1
Q

What are the four NGIPS interface modes?

A

Inline Mode, Inline-Tap Mode, Passive Mode, Passive ERSPAN Mode.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the key difference between Inline Mode and Inline-Tap Mode?

A

Inline Mode actively blocks/modifies traffic, while Inline-Tap Mode only logs and alerts without blocking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why does Inline Mode not support NAT?

A

Inline Mode functions transparently and does not modify Layer 3 addressing, making NAT unsupported.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When should you use Passive ERSPAN Mode?

A

When monitoring traffic remotely without direct Layer 2 connectivity by forwarding mirrored traffic over an IP network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What happens to traffic if Snort is down and Fail-Open (Down) is enabled?

A

Traffic is allowed to pass uninspected instead of being dropped.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you verify the current Inline Set configuration?

A

Use the command show inline-set to display the summary of the configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why must all interfaces related to Asynchronous Traffic be added to an Inline Set?

A

To ensure NGIPS correctly correlates ingress and egress traffic, preventing packet drops.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the primary use case for Passive Mode?

A

To monitor and detect threats without modifying or blocking live traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the main purpose of Passive ERSPAN Mode?

A

It allows remote traffic monitoring by encapsulating mirrored traffic and forwarding it over an IP network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which protocol does ERSPAN use to encapsulate mirrored traffic?

A

ERSPAN uses GRE (Generic Routing Encapsulation) to transport mirrored traffic over an IP network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a key requirement for ERSPAN Mode to function correctly?

A

The mirrored traffic must be encapsulated and forwarded over an IP network to NGIPS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between Fail-Open (Busy) and Fail-Open (Down)?

A

Fail-Open (Busy) allows uninspected traffic if Snort is overloaded, while Fail-Open (Down) allows uninspected traffic if Snort crashes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why might you use Inline-Tap Mode instead of Passive Mode?

A

Inline-Tap Mode allows full inspection of live traffic without enforcing blocking policies, making it useful for security testing and policy evaluation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the key difference between Passive Mode and Inline-Tap Mode?

A

Passive Mode monitors mirrored traffic and cannot block threats, while Inline-Tap Mode inspects real traffic but does not actively block it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does Inline-Tap Mode inspect traffic?

A

It receives traffic directly (not mirrored) and processes it as if it were Inline Mode but does

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which mode is best for a production environment where security policies need to be tested before enabling blocking?

A

Inline-Tap Mode is best for testing security policies in a real traffic environment without impacting users.