NIDS/NIPS Flashcards
1
Q
Passive Monitoring
A
used to receive a copy of the traffic (port mirroring) to evaluate it.
2
Q
Out of Band Response
A
Once evaluated the traffic and confirms its malicious, the response will send a TCP Reset Frame to both the source of the communication and the destination. Traffic will stop unless the source sends another traffic flow between the two devices. UDP Doesn’t allow a Reset Frame.
3
Q
Prevention System
A
Stop it before it gets to the network
4
Q
Inline Monitoring
A
Sits inline and decides whether to allow or block the traffic
5
Q
Inband response
A
Malicious traffic is identified and dropped at the IPS