Courseiva
Network Security Devices →mediumMultiple Choice

GSEC Network Security Devices Practice Question

A security engineer is configuring an inline intrusion prevention system (IPS) on a 10 Gbps internal segment. During a pilot, the IPS begins dropping legitimate business traffic because its inspection engine cannot keep pace with bursts. Which deployment adjustment best preserves inline prevention while reducing false drops?

⚠ Common exam trap

The trap here is assuming that preserving availability through bypass or passive monitoring is equivalent to preserving inline prevention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tune the IPS inspection profile to match the segment's actual protocols and disable signatures for services not present on that segment.

Inline IPS overload is usually caused by inspecting traffic and signatures that do not apply to the protected segment. Profiling the segment and disabling irrelevant signatures reduces CPU and memory pressure, allowing the engine to keep up with burst traffic while still enforcing inline prevention. The other choices either remove inline enforcement or fail to address the actual capacity bottleneck, so they do not meet the requirement of preserving prevention while reducing false drops.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable fail-open bypass on the IPS so that traffic is forwarded without inspection when the inspection engine is overwhelmed.

    Why it's wrong here

    Fail-open bypass would preserve availability but defeats the purpose of inline prevention: during overload, malicious packets would pass uninspected. The scenario asks to preserve inline prevention while reducing false drops, and bypass directly removes prevention exactly when it is most needed. It addresses the symptom (dropped legitimate traffic) by disabling the control, not by improving inspection capacity or tuning the engine.

  • ✗

    Move the IPS to a passive TAP and rely on alerts to manually block offending sources at the firewall.

    Why it's wrong here

    A passive TAP eliminates inline prevention entirely; the device can only alert, not block. Manual firewall blocking is slow and cannot stop a fast-moving exploit or worm. While this removes false drops caused by inline overload, it also removes the core requirement of inline prevention. The question asks how to preserve inline prevention, so removing it from the traffic path is not a valid adjustment.

  • ✓

    Tune the IPS inspection profile to match the segment's actual protocols and disable signatures for services not present on that segment.

    Why this is correct

    Overload often comes from inspecting irrelevant protocols and signatures, which consumes CPU and causes legitimate packets to be dropped. Profiling the segment and disabling unused signatures reduces processing load without removing inline prevention. This preserves enforcement while lowering false positives and false drops. It is the targeted, operationally sound adjustment because it aligns inspection scope with actual traffic rather than disabling protection.

  • ✗

    Increase the IPS fail-closed timeout so that traffic is buffered longer during inspection spikes.

    Why it's wrong here

    Extending a timeout does not increase inspection throughput and can worsen latency and packet loss. If the engine is already saturated, longer buffering will overflow or delay sessions, causing application timeouts and more perceived drops. The root cause is inspection load, not timeout duration. This option misdiagnoses the bottleneck and would likely degrade performance further rather than reduce legitimate traffic drops.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.