test Flashcards

1
Q

What is a Host Intrusion Detection System (HIDS)?

A

software that runs on an endpoint computer and can detect attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Host intrusion prevention systems (HIPS)

A

An intrusion prevention system detects and stops harmful activities. A host intrusion prevention system (HIPS) watches over your device, blocks threats, and lets you know if action is needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A HIDS uses agents installed on the device to monitor its activity closely. It typically tracks:

A

System Calls: Requests made by programs to the operating system. HIDS checks these requests to spot suspicious behavior.

File Access: Ensures that files are accessed for legitimate reasons and not for malicious purposes.

Input/Output: Watches all data exchanges. For example, if a device that doesn’t use instant messaging suddenly tries to connect via IM, HIDS will flag this as unusual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly