NEW
Font size
WorksheetsIntrusion Detection Systems
Total questions: 20
Worksheet time: 25mins
What are Intrusion Detection Systems (IDS)?
Computer programs that detect malicious activity on a network or system
Software that monitors network traffic and identifies potential threats
Tools used to alert administrators of unauthorized access or suspicious activity
All of the above
What are the two main categories of IDS systems?
Network-based and host-based
Signature-based and anomaly-based
Protocol-based and behaviour-based
Firewalls and antivirus software
Which type of IDS system uses a predetermined set of rules or signatures to detect known malicious activity?
Anomaly-based system
Protocol-based system
Signature-based system
Behavior-based system
What is the main limitation of signature-based IDS systems?
They are less effective at detecting new or unknown threats
They require constant monitoring by administrators
They can only detect network-based threats
They are expensive to implement
What should be done to ensure the effectiveness of an IDS system?
Regularly update the system with the latest security signatures
Install multiple IDS systems for redundancy
Use only anomaly-based IDS systems
Disable firewalls and antivirus software
Goals of IDS
Mobility and allow for a stable connection
Take action and allowing an attack to the network
Identify abnormal behaviour of network or misuse of resources
Different ways to transmit data securely and safely
A network-attached system set up as a decoy to lure cyberattackers and to detect, deflect or study hacking attempts in order to gain unauthorized access to information systems.
intrusion detection system
Fly trap
Honeypot
Intruder alarm server
A computer network that uses a public telecommunication infrastructure such as the Internet to provide remote offices or individual users secure access to their organization's network.
Proxy Server
Demilitarised zone
Virtual Private Network
Quarantine Network
A physical or logical subnet that separates an internal local area network (LAN) from other untrusted networks, usually the internet.
MTPOD
VLAN
VPN
DMZ
Which of these attack occurs when a hacker inserts itself between the communications of a client and a server?
Man-in-the-Middle
IP Spoofing
Replay
Social engineering
Which type of attack trys different passwords, hoping that one will work? Some logic can be applied by trying passwords related to the person’s name, job title, hobbies or similar items.
Logic Bomb
War Dialling
Social Engineering
Brute Force
Which firewall examines packets in isolation and does not know the packet's context?
Packet Filtering
Stateful
Stateless
Proxy
A virus has been detected on a device connected to a network. What SHOULD be done first?
Run a virus scan on all shared areas
Disconnect the device from the network
Contact the user to let them know what has happened
Update the anti-virus software
Which of the following uses a number of computers over a network of infected machines to send requests to a website which would bring it offline?
Organisation can protect themselves from SQL injection attacks by downloading and installing...
An effect of an SQL injection might be...
Finds and stops possible attacks.
IPS
IDS
When an IDS alerts you but there's no problem.
False positive
Fake positive
Bad positive
Faux Positive
Which of the following assures that private information is not made available or disclosed to unauthorized individuals?
Availability
Integrity
Confidentiality
None of the above
IDS spanning several networks over a wide area.
NIDS
DIDS
HIDS
LIDS
