Security Application and Devices Flashcards
What is an IDS
Intrusion Detection System
its a device or software that monitors and analysis that data passing thru in order to identify attacks.
How many IDS are there?
Two.
Host-based IDS (HIDS)
Network-based IDS (NIDS)
What methods IDS use to detect intrusion. ?
Signature-based detection
Policy-based detection
Anomaly-based detection.
What are the 4 alerts of IDS?
True positive
True negative
False positive
False negative.
What can IDS do ?
It can only alert and log suspicious activities.
What is DLP?
DLP stands for Data Loss Prevention.
It monitors the data system while in use, at rest or in transit.
How many DLP systems are there?
Endpoint DLP
Network DLP
Discovery, and
Cloud.
Name two types of Disk Encryption?
Hardware based and Software based encryption.
What is EPP?
Endpoint Protection Platform.
its a software agent/monitoring system that performs multiple security tasks such as anti-virus, HIDS/HIPS, firewall, DLP, and file encryption.
What is UEBA?
User Entity Behavior Analytics.
Its a system that can provide automated identification activity by user accounts and computers hosts.