Best practice in CAS-005 network security design is to deploy: NIDS passively via a port mirror (SPAN port) to avoid introducing latency or failure points. NIPS inline in a strategic point, such as integrated with the main firewall, to actively block threats.This combination provides both visibility and active protection without overloading network paths.