Security Technologies Flashcards

1
Q

What is the purpose of a firewall?

A

Firewalls close off systems to scanning and entry by blocking ports or non-trusted services and apps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a host-based IDS solution do?

A

It analyzes logged events so both success and failure events can be monitored. Alerts are generated only after passing a proper threshold. Some deploy individual client apps on each host that relays findings to central IDS server, which is responsible for compiling data to identify distributed trends.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the difference between NIPS and NIDS?

A

Network Intrusion Detection Systems examine data traffic to identify unauthorized access attempts and generate alerts. Network Intrusion Prevention Systems are solutions that are intended to provide direct protection against identified attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does a file integrity checker do?

A

It detects when a file has been improperly modified. It does this by computing a cryptographic hash (like SHA-1 or MD5) for all selected files and creates a database of the hashes. The hashes are periodically recalculated and compared to the hashes in the database to check for modification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How are advanced malware tools different?

A

They use behavior-based and context-based detection methods instead of signature-based methods.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly