Quiz: Module 07 Flashcards
An intrusion detection and prevention system is one that determines whether activity is present that is contrary to organization policy and represents a(n) _____.
a. intrusion
b. policy violation
c. vulnerability
d. threat
a. intrusion
The process of adjusting an IDPS to maximize its efficiency in detecting true positives while minimizing both false positives and false negatives is known as _____.
a. clustering
b. compaction
c. filtering
d. turning
d. turning
Using a process known as ____, network-based IDPSs look for attack patterns by comparing measured activity to known signatures in their knowledge base to determine whether an attack has occurred or may be under way.
a. packet sniffing
b. port monitoring
c. anomaly detection
d. signature matching
d. signature matching
When the measured activity is outside the baseline parameters, it is said to exceed the ____ (the level at which the IDPS triggers an alert to notify the administrator).
a. baseline level
b. footprint level
c. clipping level
d. root level
c. clipping level
A process used to develop knowledge that allows an organization to understand the actions and intentions of threat actors and develop methods to prevent or mitigate cyberattacks is known as _____.
a. threat intelligence
b. penetration testing
c. risk management
d. the kill chain
a. threat intelligence
The intrusion detection and prevention system (IDPS) is like a computer data burglar alarm.
a. True
b. False
a. True
Site policies are the rules and configuration guidelines governing the implementation and operation of IDPSs within the organization.
a. True
b. False
a. True
Because IDPS technologies are well established and inexpensive, few organizations require documentation of the threat from which the organization must be protected.
a. True
b. False
b. False
An application-based IDPS monitors a single application for abnormal events.
a. True
b. False
a. True
An anomaly-based IDPS collects statistical summaries by observing traffic that is known to be abnormal.
a. True
b. False
b. False