正解:A
IPS can only protect against known host and application-based attacks and exploits. IPS inspects traffic against signatures and anomalies, it does cover a broad spectrum of attack types, most of them signature-based, and signatures alone cannot protect against zero-day attacks.
However, with network segmentation, you're able to isolate critical assets into different segments.
And when a zero-day attack occurs, you're not at risk of losing all and are able to isolate the attack's effect to one segment.s.