Intrusion Prevention 3.2 Flashcards
1
Q
An […] watches the network in real time and blocks anything that it deems an exploit / dangerous
A
Intrusion Prevention System
IPS
2
Q
If a IDS/IPS is configured as […], then data will continue to flow through it when the device fails, keeping the network running.
A
Fail Open
3
Q
If a IDS/IPS is configured as […], then data will stop flowing when the device fails, severing the connection to the network
A
Fail Closed
4
Q
Active VS Passive monitoring:
A
In active monitoring, the IPS is connected inline and examines all traffic as it passes through. IPS is used here
In Passive monitoring, a copy of the network traffic is examined using a tap or port mirror. IDS is used here