IDS & IPS Flashcards

1
Q

What does an IDS do?

A

Intrusion Detection System

Logs and alerts

Only detects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does an IPS do?

A

Intrusion Prevention System

Logs, alerts, takes action

Detects and reacts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a NIDS?

A

Network Intrusion Detection System

responsible for detecting unauthorized network access or attacks

Monitors the traffic coming in and out of a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a HIDS?

A

Host-Based IDS

configured to look at suspicious network traffic going to or from a single server or endpoint,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a WIDS?

A

Wireless IDS

focused on detecting attempts to cause a denial of service on the wireless network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Signature-Based IDS?

A

analyze traffic based on defined signatures, and they can only recognize attacks based on the previously identified attacks that exist inside of its database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the two types Signature-Based IDS are broken up into?

A
  1. Pattern matching: focus on a specific pattern of steps that are being recognized during an attack
  2. Stateful-Matching: focus on a known baseline of a system and reporting any changes to that state
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Pattern Matching more common in?

A

NIDS & WIDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Stateful Matching more commonly used with?

A

HIDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are Anomaly-Based IDS?

A

analyze traffic and compare it to a normal baseline of traffic to determine whether there is a threat that’s occurring.

aka Behavioral-Based IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are IPS?

A

Intrusion Prevention System

Scan traffic for malicious activity and take action to stop it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly