Open cardosec

Case 246B14 · Network · L1 Foundations

Firewall vs IDS vs IPS

Practise as: Explain it · Interview

Interview questionWhat is the difference between a firewall, an IDS and an IPS, and where would you place each?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Firewall enforces allow/deny policy on flows (stateful: tracks connection state); NGFW adds app and user awareness
  2. IDS inspects copies of traffic (SPAN/TAP) and alerts; being out of band it cannot drop packets inline or break traffic
  3. IPS sits inline and can drop packets or reset sessions; false positives cause outages, so tuning matters
  4. Detection methods: signatures (Snort/Suricata rules) vs anomaly/behavioral baselines
  5. Encrypted traffic blinds payload inspection; rely on metadata like JA3/JA4, SNI, and flow data

If the interviewer pushes back

  • Would you run an IPS in fail-open or fail-closed mode for a hospital network, and why?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.