IPS & IDS Concepts Flashcards

1
Q

Intrusion Detection Systems (IDS)

A

A monitoring system capable of detecting malicious traffic and generating alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Intrusion Prevention System (IPS)

A

Enhanced IDS that can not only detect malicious traffic, but block it as well

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s the best location for IDS deployment

A

SPAN port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s the best location for IPS deployment

A

gateway or proxy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Snort

A

An open-source IDS maintained by Cisco, that is capable of advanced traffic analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Suricata

A

An advances IDS & IPS capable of offline PCAP processing and various output formats. Uses rules, alerts and logs for configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Firewall

A

inspects packets based on IPs, ports, source, and destination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IPS/IDS

A

Inspects packets based on their content and signatures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Anomaly vs Protocol Detection

A

Anomaly: Searches for irregular protocols on the network
Protocol: searches protocols that do not use encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

False Positives

A

Legitimate packages identified as threats. Misconfigured rules and environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Barynard2

A

is a popular spooler used for both snort and suricata. Barnyard can reduce workload by performing data parsing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does an Analyst do?

A
  • Reviews trigger alerts
  • Investigates the cause of an alert
  • Determines if an alert is a false positive
  • Improves rules and detection processes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly