5-3 Flashcards

1
Q

a message from the analyzer indicating that an event of intrest has occured

A

alert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

the part of the ids used to manage

A

manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

the process or method by with the ids manager makes the operator aware of an alert

A

operator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

an occurrence that indicates a suspicious activity may have occurred

A

event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

is the raw information that the ids use to detect suspicious activity

A

data source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IDS can be classified based on how they respond to detected anomalies or based on how they are ______________

A

deployed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

an active ids , whichis also called an __________ will stop any traffic deemed to be malicious activity.

A

IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

you can also define IDS/IPS based on whether a single ____________ or an entire network segment is monitored

A

machine is monitored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

most well-known open-source IDS available. its software that’s installed on a server to monitor traffic. works with host based firewall. is available for Unix, Linux, Free BSD, and windows.

A

snort

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

the consule displays a continuous stream of the contents of all packets coming across the machine

A

packet sniffer mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

similar to packet sniffer mode. the difference being that the packet contents are written to a text file log rather then displayed on the console

A

packet logger

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

with _________ snort uses a heuristic approach to detecting anomalous traffic

A

network intrusion detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

cisco has 2 widely used IDS prodcuts, Cisco IDS 4200 Series Sensors and Cisco Catalyst ________ series

A

4200 and 6500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

firepower 4100 is meant for _____________. and firewpower 9000 series is meant for _________

A

smaller network // larger networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

one of the benefits to using cisco security products is their ________ across the industry

A

widespread use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly