An intrusion detection system (IDS) watches traffic or activity and raises alerts when it sees something suspicious. An intrusion prevention system (IPS) does the same analysis but can also act automatically, dropping malicious packets, resetting connections or blocking a source address. The difference comes down to placement and action: an IDS observes a copy of traffic and tells you; an IPS sits in the traffic path and stops it. Security+ regularly tests this distinction, along with how these systems detect attacks and what happens when they make mistakes.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.