Module 11: IDS and IPS Technologies Flashcards

1
Q

What is IPS?

A

Intrusion protection system this can actively stop a attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is IDS

A

Intrusion detection system it passively monitors the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Zero Day attack

A

A attack in which the user has had 0 time or days to prepare for. a new unknown hack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 2 kind of IPS implementations

A

NIPS AND HIPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is HIPS?

A

Hardware IPS - windows defender

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is NIPS

A

Network IPS - usually a router or firewall config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What 3 components must a NIPS have

A

NIC, a processor and memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 2 modes of deployment for a IPS or IDS sensor?

A

Inline mode or promiscuous mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is IPS detection and enforcement engine ?

A

the detection engine compares incoming traffic with known attack signatures that are included in the IPS attack signature package.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is IPS attack signatures package ?

A

This is a list of known attack signatures that are contained in one file which can be frequently updated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What series router can SNORT run on?

A

the Cisco 4000 series

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How does SNORT run in a router?

A

In a virtual service container which is a VM that runs on the router itself

How well did you know this?
1
Not at all
2
3
4
5
Perfectly