NEW
Font size
WorksheetsIDS
Total questions: 10
Worksheet time: 5mins
Choose the right definition on Intrusion Detection System.
Unauthorized access to an information system or attacks that originate outside the organization
Monitoring involves examining network traffic, activity, transactions, or behavior in order to detect security-related anomalies.
The process that identifies that the intrusion has occurred or is occurring.
The alarm or alert that provides notification that an intrusion has occurred on that computer or network.
IDS can be installed on either local hosts or networks.
TRUE
FALSE
"Continuously analyzes the behavior of processes and programs on a system and alerts the user if it detects any abnormal actions, at which point the user can decide whether to allow or block the activity."
This statement refer to:
Anomaly-based monitoring
Signature-based monitoring
Behavior-based monitoring
Heuristic monitoring
"Uses an algorithm to determine if a threat exists. It could trap an application that attempts to scan ports that the other methods may not catch."
This statement refer to:
Anomaly-based monitoring
Signature-based monitoring
Behavior-based monitoring
Heuristic monitoring
Define Protocol based intrusion detection system (PIDS).
typically installed on a web server, and is used in the monitoring and analysis of the protocol in use by the computing system.
consists of multiple IDS over a large network, that facilitates advanced network monitoring, incident analysis, and instant attack data.
Watches for attacks on the network.
A software-based application that runs on a local host computer that can detect an attack as it occurs.
"Consists of multiple IDS over a large network, that facilitates advanced network monitoring, incident analysis, and instant attack data."
This statement refer to:
Protocol based intrusion detection system (PIDS)
Distributed intrusion detection system (dIDS)
Network intrusion detection system (NIDS)
Host-based intrusion detection system (HIDS)
HIDSs cannot integrate with existing antivirus, antispyware, and firewalls that are installed on the local host computer.
TRUE
FALSE
"All of the IDSs communicate with each other, or with a central server that facilitates advanced network monitoring, incident analysis, and instant attack data."
This statement refer to:
HIDS
NIDS
dIDS
PIDS
Illegal login and information theft is some of events detected by HIDS.
TRUE
FALSE
Choose the advantages of HIDS
Can detect intrusions on a large scale
Can give the hackers a notice that their action may lead to legal action
Provide response and notification automatically
No requirement of dedicated hardware
