Case 246B14 · Network · L1 Foundations
Firewall vs IDS vs IPS
Practise as: Explain it · Interview
Interview questionWhat is the difference between a firewall, an IDS and an IPS, and where would you place each?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Firewall enforces allow/deny policy on flows (stateful: tracks connection state); NGFW adds app and user awareness
- IDS inspects copies of traffic (SPAN/TAP) and alerts; being out of band it cannot drop packets inline or break traffic
- IPS sits inline and can drop packets or reset sessions; false positives cause outages, so tuning matters
- Detection methods: signatures (Snort/Suricata rules) vs anomaly/behavioral baselines
- Encrypted traffic blinds payload inspection; rely on metadata like JA3/JA4, SNI, and flow data
If the interviewer pushes back
- Would you run an IPS in fail-open or fail-closed mode for a hospital network, and why?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.