13. Which of the following is NOT a method used by passive sensors to monitor traffic?
14. Which of the following is a sensor type that uses bandwidth throttling and alters malicious content?
15. Which of the following is true about an HIDPS?
monitors OS and application logs
tracks misuse by external users
sniffs packets as they enter the network
centralized configurations affect host
performance
16. Which of the following is true about an NIDPS versus an HIDPS?
an NIDPS can determine if a host attack
was successful
an HIDPS can detect intrusion attempts on
the entire network
an HIDPS can detect attacks not caught by
an NIDPS
an NIDPS can compare audit log records
17. Which of the following is an IDPS security best practice?
to prevent false positives, only test the
IDPS at initial configuration
all sensors should be assigned IP
addresses
communication between IDPS
components should be encrypted
log files for HIDPSs should be kept local
18. If you see a /16 in the header of a snort rule, what does it mean?
a maximum of 16 log entries should be
kept
the subnet mask is 255.255.0.0
the size of the log file is 16 MB
the detected signature is 16 bits in length
19. Why might you want to allow extra time for setting up the database in an anomaly-based system?
the installation procedure is usually
complex and time consuming
it requires special hardware that must be
custom built
to add your own custom rule base
to allow a baseline of data to be compiled
20. Which of the following is true about the steps in setting up and using an IDPS?
anomaly-based systems come with a
database of attack signatures
alerts are sent when a packet doesn’t
match a stored signature
sensors placed on network segments will
always capture every packet
false positives do not compromise
network security