
IDS/IPS
Authored by Daniel Uyo
Professional Development
Used 4+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
10 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
What is the main function of an IDS?
Block all traffic
Monitor and detect suspicious activity
Encrypt network data
Assign IP addresses
Answer explanation
The main function of an Intrusion Detection System (IDS) is to monitor and detect suspicious activity within a network, helping to identify potential security threats.
2.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
What is the main difference between IDS and IPS?
IDS blocks traffic, IPS only monitors
IDS detects only, IPS detects and blocks
IPS works offline
IDS encrypts packets
Answer explanation
The main difference is that IDS (Intrusion Detection System) detects and alerts on suspicious activity, while IPS (Intrusion Prevention System) not only detects but also actively blocks malicious traffic.
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the purpose of the SID in a Snort rule?
To define the source IP
To uniquely identify a rule
To block traffic
To encrypt packets
Answer explanation
The SID (Snort ID) in a Snort rule serves to uniquely identify that specific rule. This allows for easier management and reference, distinguishing it from other rules in the system.
4.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Snort was originally developed by who?
Bill Gates
Linus Torvalds
Martin Roesch
Elon Musk
Answer explanation
Snort, an open-source intrusion detection system, was originally developed by Martin Roesch in 1998. He created it to provide a robust network security solution, distinguishing it from the other options listed.
5.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Snort is now owned by which company?
Microsoft
IBM
Cisco
Answer explanation
Snort, an open-source intrusion detection system, is now owned by Cisco. This acquisition allows Cisco to enhance its security offerings with Snort's capabilities.
6.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Which mode of Snort only reads and displays packets on the screen?
IDS Mode
IPS Mode
Sniffer Mode
Logger Mode
Answer explanation
Sniffer Mode is the correct choice as it captures and displays packets on the screen without any processing or analysis. In contrast, IDS and IPS modes involve detection and prevention mechanisms, while Logger Mode stores packets.
7.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Which Snort rule action is used to block malicious traffic in IPS mode?
alert
pass
log
drop
Answer explanation
The correct action to block malicious traffic in IPS mode is 'drop'. This action prevents the traffic from reaching its destination, effectively stopping the threat, unlike 'alert', 'pass', or 'log', which do not block traffic.
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?