312-49 · Question #327
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
The correct answer is B. Active IDS. An Active IDS (also called an Intrusion Prevention System or IPS) does not merely detect and alert - it takes automated defensive action in response to detected threats, such as terminating TCP connections, blocking source IPs, or resetting sessions. A Passive IDS (A) only…
Question
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
Options
- APassive IDS
- BActive IDS
- CNIPS
- DProgressive IDS
How the community answered
(19 responses)- A5% (1)
- B89% (17)
- D5% (1)
Explanation
An Active IDS (also called an Intrusion Prevention System or IPS) does not merely detect and alert - it takes automated defensive action in response to detected threats, such as terminating TCP connections, blocking source IPs, or resetting sessions. A Passive IDS (A) only monitors traffic and generates alerts without intervening. The fact that the connection was cut off is direct evidence of an active response mechanism. Option C (NIPS) is a valid term for network-based IPS, but B (Active IDS) is the answer the question is testing for.
Topics
Community Discussion
No community discussion yet for this question.