ch4 Flashcards
(4 cards)
1
Q
What Does “Out-of-Band” Mean in Context of IDS?
A
“Out-of-band” means the IDS is not sitting directly in the path of network traffic. Instead, it is passively monitoring by receiving a copy of the traffic via a network tap or port mirroring.
OOB is how IDS receive network traffic. The network traffic doesn’t go through the IDS.
2
Q
what types of controls are IPS and IDS?
A
for IDS it is detective. for IPS is it preventive
3
Q
how does IDS location in a network differ from IPS?
A
- IDS or NIDS is out-of-band meaning it is passively listening to network traffic going by. This means the NIPS is getting a copy of the network traffic. It is typically not able to prevent attacks. It is however sometimes able to takes measures against the attack after it has been detected.
- IPS or NIPS is in-line to the network traffic meaning the network traffic has to pass through the IPS or NIPS. NIPS has ability to prevent attacks because it can inspect packets and prevent them from moving into the private network.
4
Q
what is a zero day vulnerability?
A
this is a attack that has just been unleashed and is seen for the first time. because this attack is seen for the first time nobody has had a chance to develop any counter measures.