A Host-based Intrusion Prevention System (HIPS) protects individual devices by monitoring and preventing malicious activity directly on the host. It is ideal for protecting traveling employees' devices outside the corporate network. Isolation (A) and segmentation (B) apply to networks, and ACL (Access Control List) (C) restricts network traffic but does not provide host-level protection. HIPS is emphasized in Security Operations for endpoint protection#6:Chapter 11 CompTIA Security+ Study Guide#.