An IDS passively monitors copies of traffic and raises alerts, leaving response to administrators. An IPS sits inline on the traffic path, so it can drop malicious packets or reset connections in real time. That inline blocking capability, absent from an alert-only IDS, is the defining difference the question asks for.
Why this answer
The primary difference is that an IDS (Intrusion Detection System) is passive and only alerts on suspicious activity, while an IPS (Intrusion Prevention System) is inline and can actively block or drop malicious traffic. Both can monitor network or host activity, but the key distinction is the response capability: detect vs. detect and prevent.
Exam trap
The trap is confusing the deployment mode (inline vs. out-of-band) with the response capability; the exam tests that the key difference is alert-only vs. block, not speed, form factor, or scope.
How to eliminate wrong answers
Option A is wrong because speed is not the defining difference; both can operate at similar speeds, and an IPS may introduce latency due to inline processing. Option B is wrong because both IDS and IPS can be hardware or software; the deployment form factor is not the primary difference. Option C is wrong because both IDS and IPS can monitor hosts or networks (HIDS/NIDS, HIPS/NIPS); the scope is not the defining difference.