Module 11 Flashcards

1
Q

What are zero-day attacks?

A

A cyberattack that tries to exploit software vulnerabilities that are unknown or undisclosed by the software vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What can help to identify whether an exploit has occurred, the diagnostic features of the exploit, and the extent of the damage within the enterprise?

A

Logfiles generated by the devices at each layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How can the information gathered by log files help?

A

They help to inform measures taken in response to the exploit. Ex. Containment and mitigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why was Intrusion Detection System (IDS) implemented?

A

To passively monitor the traffic on a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does an IDS enabled device do?

A

It copies the traffic stream and analyzes the copied traffic rather than the actual forwarded packet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When IDS works offline, what does it do?

A

It compares the captured traffic stream with known malicious signatures (similar to software that checks for viruses)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why is an IDS device physically positioned in the network?

A

The traffic needs to be mirrored in order to reach it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why might network traffic not pass through an IDS?

A

The traffic is not mirrored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is a lot or very little latency added to network traffic flow?

A

Very little

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens after traffic is monitored, logged, and maybe reported to the IDS with something malicious?

A

Nothing. The IDS does not take action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly