Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Intrusion Detection and Prevention Systems

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What is the primary function of an Intrusion Detection System (IDS)?

a)

To prevent all attacks

b)

To manage user accounts

c)

To monitor and analyze events for signs of incidents

d)

To create backups of data

2.

What does an Intrusion Prevention System (IPS) do that an IDS does not?

a)

Logs information about attacks

b)

Attempts to stop possible incidents

c)

Analyzes network traffic

d)

Detects unauthorized access

3.

Which of the following is a characteristic of signature-based detection?

a)

It uses statistical methods to identify anomalies

b)

It requires constant updates to profiles

c)

It compares observed events against known attack patterns

d)

It detects previously unknown attacks

4.

What is a false positive in the context of IDPS?

a)

Correctly identifying a malicious activity

b)

Identifying a benign activity as malicious

c)

Logging an event without analysis

d)

Failing to detect a real attack

5.

What is the purpose of tuning an IDPS?

a)

To enhance user interface

b)

To increase the number of alerts

c)

To improve detection accuracy

d)

To disable all detection features

6.

Which detection methodology uses profiles of normal behavior?

a)

Network behavior analysis

b)

Stateful protocol analysis

c)

Anomaly-based detection

d)

Signature-based detection

7.

What is the main drawback of stateful protocol analysis?

a)

It cannot detect any attacks

b)

It requires no configuration

c)

It is resource-intensive

d)

It is only effective for known attacks

8.

What type of IDPS monitors network traffic for specific segments?

a)

Network-Based IDPS

b)

Behavior Analysis IDPS

c)

Wireless IDPS

d)

Host-Based IDPS

9.

Which of the following is a limitation of wireless IDPS?

a)

It has no false positives

b)

It is less accurate than wired IDPS

c)

It can monitor all channels simultaneously

d)

It cannot detect attacks on wired networks

10.

What is the primary function of a management server in an IDPS?

a)

To provide user interfaces

b)

To analyze network traffic

c)

To receive and manage information from sensors

d)

To monitor individual hosts

11.

What is a common method used by an IPS to stop an attack?

a)

Changing the security environment

b)

Logging the attack details

c)

Sending alerts to administrators

d)

Collecting more data

12.

Which type of IDPS is most commonly deployed on critical hosts?

a)

Behavior Analysis IDPS

b)

Host-Based IDPS

c)

Wireless IDPS

d)

Network-Based IDPS

13.

What is the role of a console in an IDPS?

a)

To perform data analysis

b)

To monitor network traffic

c)

To store event information

d)

To provide an interface for users and administrators

14.

What is the main purpose of a blacklist in IDPS?

a)

To analyze network performance

b)

To monitor user activity

c)

To block known malicious entities

d)

To allow all traffic

15.

What is the primary difference between a Network-Based IDPS and a Host-Based IDPS?

a)

Network-Based IDPS monitors traffic on the network, while Host-Based IDPS monitors individual devices

b)

Host-Based IDPS is more effective against network attacks

c)

Network-Based IDPS requires more configuration than Host-Based IDPS

d)

Host-Based IDPS can analyze network traffic

16.

Which type of attack is most likely to be detected by an anomaly-based detection system?

a)

Phishing attempts

b)

Unusual patterns of network traffic

c)

Zero-day exploits

d)

Known malware attacks

17.

What is the significance of a whitelist in an IDPS?

a)

To allow only known safe entities

b)

To block all traffic

c)

To monitor all network activity

d)

To identify potential threats

18.

What is the primary advantage of using anomaly-based detection over signature-based detection?

a)

It requires less computational power

b)

It is easier to configure

c)

It can detect previously unknown attacks

d)

It generates fewer false positives

19.

Which type of IDPS is best suited for monitoring wireless networks?

a)

Behavior Analysis IDPS

b)

Network-Based IDPS

c)

Host-Based IDPS

d)

Wireless IDPS

20.

What is the main purpose of an alert in an IDPS?

a)

To inform administrators of potential security incidents

b)

To block malicious traffic

c)

To log all network activity

d)

To analyze user behavior