Courseiva
Network Security Devices →mediumMultiple Choice

GSEC Network Security Devices Practice Question

A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?

⚠ Common exam trap

The trap here is assuming that any inline IPS can handle 10 Gbps without verifying its throughput and latency specifications, or overlooking the need for a hardware bypass to prevent a single point of failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the IPS can perform inspection at line rate with low latency and has a hardware bypass mechanism to maintain availability if it fails.

An inline IPS on a critical 10 Gbps link must inspect and block at line rate while not introducing latency that disrupts real-time applications. A hardware bypass or fail-to-wire mechanism is essential to maintain network availability if the IPS fails, which is especially important in a hospital setting. Performance and availability are the key considerations for this deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify the IPS can perform inspection at line rate with low latency and has a hardware bypass mechanism to maintain availability if it fails.

    Why this is correct

    For an inline IPS on a high-speed clinical link, the device must handle 10 Gbps of traffic without adding latency that affects real-time monitoring. A hardware bypass or fail-to-wire capability ensures that if the IPS fails or loses power, traffic continues to flow, preserving patient safety. This combination of performance and availability is the primary deployment consideration for this scenario.

  • ✗

    Configure the IPS in tap mode with a fail-open bypass so it can inspect traffic without being in the forwarding path.

    Why it's wrong here

    Tap mode copies traffic to the IPS but does not allow inline blocking; the IPS cannot drop malicious packets because it is not in the forwarding path. A fail-open bypass only helps availability if the IPS fails, but it does not satisfy the requirement to block exploits. This option would leave the network vulnerable to attacks that the IPS detects but cannot prevent.

  • ✗

    Enable full packet capture on the IPS to record all traffic for forensic analysis, accepting the performance overhead.

    Why it's wrong here

    Full packet capture is storage-intensive and can degrade throughput, which is unacceptable on a latency-sensitive 10 Gbps link. While forensic data is valuable, it is not the most critical factor when the priority is blocking exploits without disrupting patient monitoring. This option would likely introduce delays and potential packet loss, harming real-time clinical operations.

  • ✗

    Deploy the IPS in promiscuous mode and rely on span ports to mirror traffic from the core switch.

    Why it's wrong here

    Promiscuous mode with span ports is a passive monitoring deployment; the IPS can detect but not block attacks because it is not inline. This fails the requirement to block exploits. Additionally, span ports can drop packets under high load, reducing inspection accuracy. The scenario explicitly requires inline blocking, so this approach is unsuitable.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.