nerdexam
EC-Council

312-49 · Question #45

An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well

The correct answer is B. Host-based intrusion detection. A Host-based Intrusion Detection System (HIDS) monitors and audits events occurring on a specific individual host, such as a server or workstation. It analyzes system calls, application logs, file-system changes, and user activity on that machine. In contrast, a Network-based IDS

Submitted by carlos_mx· Apr 18, 2026Computer Forensics Investigation Process

Question

An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse. Which of the following intrusion detection systems audit events that occur on a specific host?

Options

  • ANetwork-based intrusion detection
  • BHost-based intrusion detection
  • CLog file monitoring
  • DFile integrity checking

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    90% (18)
  • D
    5% (1)

Explanation

A Host-based Intrusion Detection System (HIDS) monitors and audits events occurring on a specific individual host, such as a server or workstation. It analyzes system calls, application logs, file-system changes, and user activity on that machine. In contrast, a Network-based IDS (NIDS) monitors traffic across the network. Log file monitoring and file integrity checking are techniques that a HIDS may use, but they are components/methods rather than the overarching IDS category that audits host-specific events.

Topics

#Intrusion Detection System (IDS)#Host-based IDS (HIDS)#Security Monitoring#Incident Detection

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice