An administrator is reviewing the logs for a content management system that supports the organization’s public-facing website. The administrator is concerned
about the number of attempted login failures from other countries for administrator accounts. Which of the following capabilities is BEST to implement if the
administrator wants the system to dynamically react to such attacks?

A.
Netflow-based rate limiting
B.
Disable generic administrative accounts
C.
Automated log analysis
D.
Intrusion prevention system
answer for this is D – IPS.
1
0
I agree – answer should be D – IPS.
1
0
An intrusion prevention system isn’t going to work dynamically.
NetFlow does an anomaly intrusion detection system which means it could dynamically react, just not prevent which I think satisfies the question asked
0
1