312-49 · Question #45
An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well
The correct answer is B. Host-based intrusion detection. A Host-based Intrusion Detection System (HIDS) monitors and audits events occurring on a specific individual host, such as a server or workstation. It analyzes system calls, application logs, file-system changes, and user activity on that machine. In contrast, a Network-based IDS
Question
An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse. Which of the following intrusion detection systems audit events that occur on a specific host?
Options
- ANetwork-based intrusion detection
- BHost-based intrusion detection
- CLog file monitoring
- DFile integrity checking
How the community answered
(20 responses)- A5% (1)
- B90% (18)
- D5% (1)
Explanation
A Host-based Intrusion Detection System (HIDS) monitors and audits events occurring on a specific individual host, such as a server or workstation. It analyzes system calls, application logs, file-system changes, and user activity on that machine. In contrast, a Network-based IDS (NIDS) monitors traffic across the network. Log file monitoring and file integrity checking are techniques that a HIDS may use, but they are components/methods rather than the overarching IDS category that audits host-specific events.
Topics
Community Discussion
No community discussion yet for this question.