Module 12: IPS Operation and Implementation Flashcards

1
Q

What is an IPS Signature?

A

Malicious traffic displays signatures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 3 distinctive attributes for a IPS signature?

TTA

A

Type - Atomic or Composite
Trigger - Alarm
Action - What the IPS will do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Atomic Signature?

A

Simplest type - can just be 1 packet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Composite Signature

A

Stateful signature - several pieces of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the four alert classifications

A
True positive (desirable)
True negative (desirable)
False positive (undesirable)
False negative (dangerous)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Snort?

A

A open source network IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What 2 components make up Snort?

A

Snort Engine

Snort rule software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 2 types of Snort Rule Sets?

A

Community Rule Set - free

Subscriber Rule Set - paid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 3 Snort IDS Actions (ALP)

A

Alert
Log
Pass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 3 Snort IPS Actions

A

Drop
Reject - block and log
Sdrop - block dont log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What 2 interfaces does Snort run on?

A

Management Interface

Data Interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the Snort Management Interface?

A

this is the interface used to sourced logs and for retrieving signature updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Snort Data Interface

A

This is the interface that is used to send user traffic between the Snort virtual container service and the router forwarding plane.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is threat protection mode with Snort?

A

Snort will be in IPS mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is threat detection mode with Snort

A

Snort will be in IDS mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly