A security team is deploying an inline intrusion prevention system (IPS) on a critical 10 Gbps link and must minimize the risk of the IPS becoming a single point of failure while still blocking malicious traffic. Which TWO design characteristics should the team ensure are in place? (Choose two.)
An inline IPS must keep up with line rate; otherwise it will drop legitimate packets or introduce unacceptable latency. Sizing and tuning the inspection engine for the full 10 Gbps plus expected bursts ensures the device does not become a performance bottleneck or a de facto denial of service. This directly supports the goal of maintaining availability while enforcing prevention. It is a fundamental capacity planning requirement for inline IPS on critical high-speed links.
Why this answer
Inline IPS on a critical 10 Gbps link must both survive failure and keep up with traffic. A hardware bypass or fail-open mechanism ensures traffic continues if the device fails, and proper sizing and tuning ensure the inspection engine can process line rate and bursts without dropping legitimate packets. Passive deployment cannot block, dropping uninspectable traffic harms availability, and out-of-band management, while good practice, does not address the data-plane requirements.
Exam trap
The trap here is treating passive monitoring or strict fail-closed inspection as equivalent to a resilient inline prevention design.