Courseiva
Network Security Devices →hardMultiple Select

GSEC Network Security Devices Practice Question

A security team is deploying an inline intrusion prevention system (IPS) on a critical 10 Gbps link and must minimize the risk of the IPS becoming a single point of failure while still blocking malicious traffic. Which TWO design characteristics should the team ensure are in place? (Choose two.)

⚠ Common exam trap

The trap here is treating passive monitoring or strict fail-closed inspection as equivalent to a resilient inline prevention design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPS inspection engine is sized and tuned so that it can process the full 10 Gbps line rate with expected burst traffic.

Inline IPS on a critical 10 Gbps link must both survive failure and keep up with traffic. A hardware bypass or fail-open mechanism ensures traffic continues if the device fails, and proper sizing and tuning ensure the inspection engine can process line rate and bursts without dropping legitimate packets. Passive deployment cannot block, dropping uninspectable traffic harms availability, and out-of-band management, while good practice, does not address the data-plane requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The IPS inspection engine is sized and tuned so that it can process the full 10 Gbps line rate with expected burst traffic.

    Why this is correct

    An inline IPS must keep up with line rate; otherwise it will drop legitimate packets or introduce unacceptable latency. Sizing and tuning the inspection engine for the full 10 Gbps plus expected bursts ensures the device does not become a performance bottleneck or a de facto denial of service. This directly supports the goal of maintaining availability while enforcing prevention. It is a fundamental capacity planning requirement for inline IPS on critical high-speed links.

  • ✗

    The IPS is configured to drop all traffic that it cannot inspect, including encrypted sessions it cannot decrypt.

    Why it's wrong here

    Dropping all uninspectable traffic, including encrypted sessions, would cause severe availability problems and block legitimate business communication. The goal is to minimize single-point-of-failure risk and still block malicious traffic, not to enforce a fail-closed policy on all uninspected flows. Such a configuration would likely create outages and is not a recommended design characteristic for an inline IPS on a critical link. It confuses strict enforcement with availability preservation.

  • ✗

    The IPS is managed out-of-band on a separate management VLAN with restricted access.

    Why it's wrong here

    Out-of-band management on a restricted VLAN is a good security practice, but it does not address the single-point-of-failure or line-rate requirements for inline traffic. It improves management security and availability of the management plane, yet it does not ensure data-plane continuity or inspection capacity. Because the question asks for design characteristics that minimize single-point-of-failure risk while still blocking traffic, this option is not one of the two required characteristics.

  • ✓

    The IPS supports a hardware bypass or fail-open mechanism that forwards traffic if the device loses power or fails.

    Why this is correct

    Hardware bypass or fail-open ensures that if the IPS fails or loses power, traffic continues to flow, preventing a complete outage. This directly addresses the single-point-of-failure concern while allowing the IPS to block malicious traffic during normal operation. It is a standard requirement for inline IPS on critical links because availability must be preserved even when the security control is unavailable. Without it, an IPS failure could halt all business traffic.

  • ✗

    The IPS is deployed in passive mode with a span port so that it can alert without affecting traffic flow.

    Why it's wrong here

    Passive mode with a span port avoids becoming a single point of failure, but it also cannot block malicious traffic inline. The scenario requires both minimizing single-point-of-failure risk and still blocking malicious traffic. Passive deployment removes the inline enforcement capability, so it does not satisfy the blocking requirement. It may be useful for monitoring, but it is not a valid inline IPS design characteristic for this requirement.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.