8 - Firewall/Intrusion Flashcards
1
Q
Packet filtering vs stateful inspection
A
Stateful tightens rules for TCP traffic by creating directory of TCP connections
Records information
2
Q
Anomaly detection vs misuse detection
A
Anomaly detection - collect data on users, determine if new behavior is consistent, not as widely used
Misuse detection - identify malware that has patterns we know
3
Q
Firewall deployments
A
Yes
4
Q
Base rate fallacy
A
Can’t ignore probability of no attack when there is an alert
There is a normal amount of alerts in steady state