nerdexam
EC-Council

312-38 · Question #74

Which of the following tools is an open source network intrusion prevention and detection system that operates as a network sniffer and logs activities of the network that is matched with the…

The correct answer is C. Snort. Snort is the correct answer because it is a widely-used open source network intrusion detection and prevention system (IDS/IPS) that functions as a packet sniffer, logging network traffic and matching it against a library of predefined rule-based signatures to detect malicious…

Network Security Monitoring and Analysis

Question

Which of the following tools is an open source network intrusion prevention and detection system that operates as a network sniffer and logs activities of the network that is matched with the predefined signatures?

Options

  • ADsniff
  • BKisMAC
  • CSnort
  • DKismet

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    93% (53)
  • D
    2% (1)

Explanation

Snort is the correct answer because it is a widely-used open source network intrusion detection and prevention system (IDS/IPS) that functions as a packet sniffer, logging network traffic and matching it against a library of predefined rule-based signatures to detect malicious activity. Dsniff (A) is a collection of tools for network auditing and password sniffing, not an IDS/IPS with signature-based detection. KisMAC (B) is a macOS-specific wireless network scanner focused on Wi-Fi discovery and auditing, not general network intrusion detection. Kismet (D) is also a wireless network detector and sniffer, but it focuses on passive Wi-Fi scanning rather than signature-based intrusion prevention.

Memory tip: Think "Snort = Sniff + Sort" - it sniffs packets and sorts them against signatures to detect threats. The name even sounds like a pig sniffing out danger, which is fitting since Snort's mascot is a pig.

Topics

#IDS/IPS#Snort#Signature-Based Detection#Network Monitoring

Community Discussion

No community discussion yet for this question.

Full 312-38 Practice