NIDS/NIPS Flashcards

1
Q

Passive Monitoring

A

used to receive a copy of the traffic (port mirroring) to evaluate it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Out of Band Response

A

Once evaluated the traffic and confirms its malicious, the response will send a TCP Reset Frame to both the source of the communication and the destination. Traffic will stop unless the source sends another traffic flow between the two devices. UDP Doesn’t allow a Reset Frame.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Prevention System

A

Stop it before it gets to the network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Inline Monitoring

A

Sits inline and decides whether to allow or block the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Inband response

A

Malicious traffic is identified and dropped at the IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly