Domain 6 set 1 Flashcards
5 steps in an attack
- Reconnaissance
- Foot-printing (Mapping the Network) Nmap
- Fingerprinting (port scanning)
- Vulnerability assessment (identifying weaknesses)
- The Attack
Red Team?
ATTACK
Blue Team
Defend
IDS is passive or active ?
passive
IDS and IPS need what to view traffic
Port mirroring / span
the interface need to be in what mode for a IDS
Promiscuous Mode
use what ids type for a single system
Host-based IDS (HIDS)
use what ids type for a network segment
Network-based IDS (NDIS)
Analysis Engine on a IDS does what?
Analyzes data collected by the sensor, determines if there is suspicious activity
the 4 parts of an IDS
- Sensors
- Analysis Engine
- Signature Database
- User Interface and reporting
What IDS decrypt data?
Host-based IDS (HIDS)
A sensor is sometimes called what
Traffic Collector
the two analysis engines?
- Pattern matching
2. profile matching
Anomaly / behavior is what type of analysis engines?
profile matching
analysis engine that needs a baseline
profile matching