IC34M05 - Intrusion Detection Systems Flashcards

1
Q

IDS Best Practices

A
  • Distributed Deployment
  • Use SCADA IDS Signatures
  • Be careful not to block necessary traffic when using IPS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does NIDS stand for?
1. Network Instrusion Deployment System
2. New Invention Deploy Safely
3. Network Instrusion Detection System
4. Never Identify Defense Strategy

A

Network Instrusion Detection System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an Instrusion Detection System (IDS)?
1. A warning system of excess heat in a server room
2. A device or software program that controls the flow of traffic between networks or network devices
3. Tools to detect attemps to break into misuse a computer system
4. A device that controls the flow of traffic between networks

A

Tools to detect attemps to break into misuse a computer system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The two main types of IDS are?
1. Internet & Computer
2. Network & Host-based
3. Cloud-based & Local
4. Inbound & Outbound

A

Network & Host-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which is not an IDS best practice?
1. Be sure not to block necessary traffic with Instrusion Prevention Systems
2. Be sure to block necessary traffic with Intrussion Prevention Systems
3. Install NIDS as zone entry points
4. Enhance signature with SCADA IDS signatures

A

Be sure to block necessary traffic with Intrussion Prevention Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which is an attribute of HIDS?
1. Requires hardware
2. Bandwith dependent
3. Responds after suspicious activity occurs
4. High false positive rate
5. Broad scope

A

Responds after suspicious activity occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly