312-38 · Question #74
Which of the following tools is an open source network intrusion prevention and detection system that operates as a network sniffer and logs activities of the network that is matched with the…
The correct answer is C. Snort. Snort is the correct answer because it is a widely-used open source network intrusion detection and prevention system (IDS/IPS) that functions as a packet sniffer, logging network traffic and matching it against a library of predefined rule-based signatures to detect malicious…
Question
Options
- ADsniff
- BKisMAC
- CSnort
- DKismet
How the community answered
(57 responses)- A4% (2)
- B2% (1)
- C93% (53)
- D2% (1)
Explanation
Snort is the correct answer because it is a widely-used open source network intrusion detection and prevention system (IDS/IPS) that functions as a packet sniffer, logging network traffic and matching it against a library of predefined rule-based signatures to detect malicious activity. Dsniff (A) is a collection of tools for network auditing and password sniffing, not an IDS/IPS with signature-based detection. KisMAC (B) is a macOS-specific wireless network scanner focused on Wi-Fi discovery and auditing, not general network intrusion detection. Kismet (D) is also a wireless network detector and sniffer, but it focuses on passive Wi-Fi scanning rather than signature-based intrusion prevention.
Memory tip: Think "Snort = Sniff + Sort" - it sniffs packets and sorts them against signatures to detect threats. The name even sounds like a pig sniffing out danger, which is fitting since Snort's mascot is a pig.
Topics
Community Discussion
No community discussion yet for this question.