200-201 · Question #294
Refer to the exhibit. Which technology produced the log?
The correct answer is B. IPS/IDS. The log entry, with its specific format like '[1:2009363:1] ET POLICY PE EXE or DLL download HTTP', is characteristic of an Intrusion Detection/Prevention System (IDS/IPS).
Question
Refer to the exhibit. Which technology produced the log?
Exhibit
Options
- Aantivirus
- BIPS/IDS
- Cfirewall
- Dproxy
How the community answered
(40 responses)- A13% (5)
- B80% (32)
- C3% (1)
- D5% (2)
Why each option
The log entry, with its specific format like '[1:2009363:1] ET POLICY PE EXE or DLL download HTTP', is characteristic of an Intrusion Detection/Prevention System (IDS/IPS).
Antivirus software primarily performs endpoint scanning and remediation, not network traffic analysis and signature-based alerting in this format.
The log format, specifically the `[GID:SID:REV]` notation (e.g., `[1:2009363:1]`) and the signature-based alert message 'ET POLICY PE EXE or DLL download HTTP', are hallmarks of an IDS/IPS like Snort or Suricata, which detect suspicious network activity based on predefined rules and signatures.
Firewalls primarily enforce access control rules based on IP addresses, ports, and protocols, and do not typically generate detailed content-based policy alerts with specific signature IDs like those shown.
A proxy server mediates network connections and logs requests, but it does not generate these types of signature-driven security alerts indicative of threat detection.
Concept tested: Log analysis, IDS/IPS identification
Source: https://www.snort.org/documentation
Topics
Community Discussion
No community discussion yet for this question.
