NEW
Font size
WorksheetsChapter 2 - IT Security - Pre Quiz
Total questions: 15
Worksheet time: 8mins
What is the primary purpose of an Intrusion Detection System (IDS)?
To prevent all cyber attacks
To detect a wide range of security violations
To encrypt network traffic
To manage network bandwidth
What is a key advantage of Host-Based IDS?
Lower cost
More detailed logging
Wider range of detection
Easier deployment
What is a key consideration when placing Network-Based IDS?
It must be placed where outbound packets are invisible
It must be placed where inbound and outbound packets are visible
It must be placed after encryption points
It must be placed only at network endpoints
Which detection method takes the context of the established session into account?
Pattern Matching
Stateful Pattern Matching
Protocol Decode based analysis
Heuristic based analysis (based on practical experience and knowledge)
Which of the following is NOT one of the main benefits of implementing an IDS?
Early detection
Deterrence
Network acceleration
Future improvement through information collection
What is a key advantage of Network-Based IDS over Host-Based IDS?
More detailed logging
Lower cost of deployment
Better detection of unknown attacks
Increased recovery capabilities
What is a key advantage of Application Firewalls/IDS?
High network performance
Easy configuration
Very granular policy setting
No need for updates
What is the main difference between IPS and IDS?
IPS is older technology
IPS is reactive while IDS is proactive
IPS is proactive while IDS tends to be reactive
They are exactly the same
Layer Seven (Application layer) Switches are especially effective against which type of attack?
Buffer overflow attacks
SQL injection
DoS attacks
Man-in-the-middle attacks
Which type of IPS combines the features of host-based application firewall/IDS and layer seven switch?
Inline IDS
Deceptive Applications
Hybrid Switches
Network-based application IDS
What is a honeypot?
A system designed to detect all types of malware
A system designed to attract attackers
A type of firewall
A network monitoring tool
In honeypot deployment strategies, what is the "Minefield" approach?
Creating an entire network of honeypots
Pairing each critical server with a honeypot
Scattering honeypots throughout actual systems
Using honeypots as firewalls
Which type of honeypot is described as the simplest form but can be used to launch attacks when compromised?
Facade
Instrumented Systems
Sacrificial Lamb
Shield
In the "Shield" honeypot deployment strategy, what happens to legitimate port traffic?
It's blocked
It's sent to the honeypot
It's sent to the real host
It's duplicated to both hosts
Which of the following is true about Honeynet deployment strategy?
It pairs each server with a honeypot
It creates an entire network using honeypots
It only protects the network perimeter
It replaces the existing network infrastructure
