A network administrator wants to implement an intrusion detection system that can monitor network traffic without impacting network performance or flow. Which of the following device attributes would be most suitable for this requirement?
A tap passive device monitors network traffic by copying data from the network without being in the direct flow of traffic. This means it does not impact network performance or flow because it is not inline with the traffic; instead, it passively receives a copy of the data. Inline devices, whether active or passive, are placed directly in the path of network traffic and can introduce latency or points of failure. Active devices can take actions such as blocking or modifying traffic, which could impact performance. Therefore, a tap passive device is the most suitable for monitoring without affecting network performance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an intrusion detection system (IDS)?
Open an interactive chat with Bash
What are the differences between 'tap' and 'inline' devices?
Open an interactive chat with Bash
How do passive devices improve network performance monitoring?