9.1: Quiz IDS/IPS Flashcards

1
Q

(1)An organization has installed a IDS which monitor general patterns of activity and creates the database. Which of the following intrusion detection systems (IDSs) has this feature?

A. Packet filtering
B. Signature-based
C. Statistical-based
D. Neural networks

A

Answer: D. Neural networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

(2) The component of an IDS that collects the data is:

A. Sensor
B. Analyzer
C. User interface
D. Administration console

A

Answer: A. Sensor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

(3)Even for normal activity, which of the following intrusion detection systems (IDSs) will MOST likely generate false alarms?

A. Statistical-based
B. Signature-based
C. Neural network
D. Host-based

A

Answer: A. Statistical-based

Explanation:
Statistical based IDS determine normal (known and expected) behaviour of the system. Any activity which falls outside the scope of normal behaviour is flagged as intrusion. Statistical based IDS is most likely to generate false positive (i.e. false alarm) as compared to other IDS. Since normal network activity may include unexpected behaviour (e.g., frequent download by multiple users), these activities will be flagged as suspicious.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

(4)An IS auditor is reviewing installation of intrusion detection system (IDS). Which of the following
is a GREATEST concern?

A. number of non-alarming events identified as alarming
B. system not able to identify the alarming attacks
C. automated tool is used for analysis of reports/logs
D. traffic from known source is blocked by IDS

A

Answer: B. system not able to identify the alarming attacks

Explanation:
Major concern will be of system not able to identify the alarming attacks. They present a higher risk because attacks will be unnoticed and no action will be taken to address the attack. High false positive is a concern but not a major concern. Also, logs/reports are first analyzed by an automated tool to eliminate known false-positives, which generally are not a problem, and an IDS does not block any traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

(5)An organization wants to detect attack attempts that the firewall is unable to recognize. A network intrusion detection system (IDS) between the:

A. Internet and the firewall
B. firewall and organization’s internal network
C. Internet and the IDS.
D. IDS and internal network

A

Answer: B. firewall and organization’s internal network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

(6) Which of the following is a function of an intrusion detection system (IDS)?

A. obtain evidence on intrusive activity
B. control the access on the basis of defined rule
C. blocking access to websites for unauthorized users
D.preventing access to servers for unauthorized users

A

Answer: A. obtain evidence on intrusive activity

Explanation:
Obtaining evidence on intrusive activity is a function of IDS. Other options are functions of firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

(7) Which of the following is the most routine problem in implementation of intrusion detection system (IDS)?

A. instances of false rejection rate.
B. instances of false acceptance rate.
C. instances of false positives.
D. denial-of-service attacks.

A

Answer: C. instances of false positives.

Explanation:
Main problem in operating IDSs is the recognition (detection) of events that are not really security incidents—false positives (i.e. false alarm). Option A & B are the concerns of biometric implementation. Denial of service is a type of attack and is not a problem in the operation of IDSs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

(8)Attempts of intrusion attacks and penetration threat to a network can be detected by which of the following by analysing the behaviour of the system?

A. Router
B. Intrusion detection system (IDs)
C. Stateful inspection
D. Packet filters

A

Answer: B. Intrusion detection system (IDs)

Explanation:
IDS determine normal (known and expected) behaviour of the system. Any activity which falls outside the scope of normal behaviour is flagged as intrusion. Router, Stateful inspection and packet filters are types of firewalls designed to block certain types of communications routed or passing through specific ports. It is not designed to discover someone bypassing or going under the firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

(9) To detect intrusion, BEST control would be:

A.Controlled procedure for granting user access
B.Inactive system to be automatically logged off after time limit.
C.Actively monitor unsuccessful login attempts.
D. Deactivate the user ID after specified unsuccessful login attempts.

A

Answer: C.Actively monitor unsuccessful login attempts.

Explanation: BEST method to detect the intrusion is to actively monitor the unsuccessful logins.
Deactivating the user ID is preventive method and not detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

(10)An IS auditor reviewing the implementation of IDS should be most concerned if:

A. High instances of false alarm by statistical based IDS.
B.IDS is placed between firewall and internal network.
C.IDS is used to detect encrypted traffic.
D.Signature based IDS is not able to identify new threats.

A

Answer: C.IDS is used to detect encrypted traffic.
Explanation:

IDS cannot detect attacks which are in form of encrypted traffic. So if organization has
misunderstood that IDS can detect encrypted traffic also and accordingly designed its control strategy, then it is major concern.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

(11)Of all three IDS (i.e. (i) signature (ii) statistics and (iii) neural network), neural network is more effective in detecting fraud because:

A. Intrusion is identified on the basis of known type of attacks.
B. Any activity which falls outside the scope of normal behaviour is flagged as intrusion.
C. IDS monitor the general pattern of activities and create a database and attacks problems that
require consideration of a large number of input variables.
D.IDS solves the problem where large and where large database is not required.

A

Answer: C. IDS monitor the general pattern of activities and create a database and attacks problems
that require consideration of a large number of input variables.

Explanation:
Neural networks monitor the general pattern of activities and create a database and attacks
problems that require consideration of a large number of input variables. They are capable of
capturing relationships and patterns often missed by other statistical methods. Option A is feature
of signature based IDS. Option B is feature of statistics based IDS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly