Search Header Logo

IDS/IPS

Authored by Daniel Uyo

Professional Development

Used 4+ times

IDS/IPS
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

What is the main function of an IDS?

Block all traffic

Monitor and detect suspicious activity

Encrypt network data

Assign IP addresses

Answer explanation

The main function of an Intrusion Detection System (IDS) is to monitor and detect suspicious activity within a network, helping to identify potential security threats.

2.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

What is the main difference between IDS and IPS?

IDS blocks traffic, IPS only monitors

IDS detects only, IPS detects and blocks

IPS works offline

IDS encrypts packets

Answer explanation

The main difference is that IDS (Intrusion Detection System) detects and alerts on suspicious activity, while IPS (Intrusion Prevention System) not only detects but also actively blocks malicious traffic.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the purpose of the SID in a Snort rule?

To define the source IP

To uniquely identify a rule

To block traffic

To encrypt packets

Answer explanation

The SID (Snort ID) in a Snort rule serves to uniquely identify that specific rule. This allows for easier management and reference, distinguishing it from other rules in the system.

4.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Snort was originally developed by who?

Bill Gates

Linus Torvalds

Martin Roesch

Elon Musk

Answer explanation

Snort, an open-source intrusion detection system, was originally developed by Martin Roesch in 1998. He created it to provide a robust network security solution, distinguishing it from the other options listed.

5.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Snort is now owned by which company?

Microsoft

Google

IBM

Cisco

Answer explanation

Snort, an open-source intrusion detection system, is now owned by Cisco. This acquisition allows Cisco to enhance its security offerings with Snort's capabilities.

6.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Which mode of Snort only reads and displays packets on the screen?

IDS Mode

IPS Mode

Sniffer Mode

Logger Mode

Answer explanation

Sniffer Mode is the correct choice as it captures and displays packets on the screen without any processing or analysis. In contrast, IDS and IPS modes involve detection and prevention mechanisms, while Logger Mode stores packets.

7.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Which Snort rule action is used to block malicious traffic in IPS mode?

alert

pass

log

drop

Answer explanation

The correct action to block malicious traffic in IPS mode is 'drop'. This action prevents the traffic from reaching its destination, effectively stopping the threat, unlike 'alert', 'pass', or 'log', which do not block traffic.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?