WorksheetsIntrusion Detection and Prevention Systems
Total questions: 20
Worksheet time: 10mins
What is the primary function of an Intrusion Detection System (IDS)?
To prevent all attacks
To manage user accounts
To monitor and analyze events for signs of incidents
To create backups of data
What does an Intrusion Prevention System (IPS) do that an IDS does not?
Logs information about attacks
Attempts to stop possible incidents
Analyzes network traffic
Detects unauthorized access
Which of the following is a characteristic of signature-based detection?
It uses statistical methods to identify anomalies
It requires constant updates to profiles
It compares observed events against known attack patterns
It detects previously unknown attacks
What is a false positive in the context of IDPS?
Correctly identifying a malicious activity
Identifying a benign activity as malicious
Logging an event without analysis
Failing to detect a real attack
What is the purpose of tuning an IDPS?
To enhance user interface
To increase the number of alerts
To improve detection accuracy
To disable all detection features
Which detection methodology uses profiles of normal behavior?
Network behavior analysis
Stateful protocol analysis
Anomaly-based detection
Signature-based detection
What is the main drawback of stateful protocol analysis?
It cannot detect any attacks
It requires no configuration
It is resource-intensive
It is only effective for known attacks
What type of IDPS monitors network traffic for specific segments?
Network-Based IDPS
Behavior Analysis IDPS
Wireless IDPS
Host-Based IDPS
Which of the following is a limitation of wireless IDPS?
It has no false positives
It is less accurate than wired IDPS
It can monitor all channels simultaneously
It cannot detect attacks on wired networks
What is the primary function of a management server in an IDPS?
To provide user interfaces
To analyze network traffic
To receive and manage information from sensors
To monitor individual hosts
What is a common method used by an IPS to stop an attack?
Changing the security environment
Logging the attack details
Sending alerts to administrators
Collecting more data
Which type of IDPS is most commonly deployed on critical hosts?
Behavior Analysis IDPS
Host-Based IDPS
Wireless IDPS
Network-Based IDPS
What is the role of a console in an IDPS?
To perform data analysis
To monitor network traffic
To store event information
To provide an interface for users and administrators
What is the main purpose of a blacklist in IDPS?
To analyze network performance
To monitor user activity
To block known malicious entities
To allow all traffic
What is the primary difference between a Network-Based IDPS and a Host-Based IDPS?
Network-Based IDPS monitors traffic on the network, while Host-Based IDPS monitors individual devices
Host-Based IDPS is more effective against network attacks
Network-Based IDPS requires more configuration than Host-Based IDPS
Host-Based IDPS can analyze network traffic
Which type of attack is most likely to be detected by an anomaly-based detection system?
Phishing attempts
Unusual patterns of network traffic
Zero-day exploits
Known malware attacks
What is the significance of a whitelist in an IDPS?
To allow only known safe entities
To block all traffic
To monitor all network activity
To identify potential threats
What is the primary advantage of using anomaly-based detection over signature-based detection?
It requires less computational power
It is easier to configure
It can detect previously unknown attacks
It generates fewer false positives
Which type of IDPS is best suited for monitoring wireless networks?
Behavior Analysis IDPS
Network-Based IDPS
Host-Based IDPS
Wireless IDPS
What is the main purpose of an alert in an IDPS?
To inform administrators of potential security incidents
To block malicious traffic
To log all network activity
To analyze user behavior
