312-50V10 · Question #316
Which of the following identifies the three modes in which Snort can be configured to run?
The correct answer is A. Sniffer, Packet Logger, and Network Intrusion Detection System. Snort operates in three distinct modes - Sniffer, Packet Logger, and Network Intrusion Detection System (NIDS) - each providing increasing levels of traffic analysis capability.
Question
Which of the following identifies the three modes in which Snort can be configured to run?
Options
- ASniffer, Packet Logger, and Network Intrusion Detection System
- BSniffer, Network Intrusion Detection System, and Host Intrusion Detection System
- CSniffer, Host Intrusion Prevention System, and Network Intrusion Prevention System
- DSniffer, Packet Logger, and Host Intrusion Prevention System
How the community answered
(35 responses)- A91% (32)
- C6% (2)
- D3% (1)
Why each option
Snort operates in three distinct modes - Sniffer, Packet Logger, and Network Intrusion Detection System (NIDS) - each providing increasing levels of traffic analysis capability.
Snort's three official operational modes are Sniffer mode (reads packets off the network and displays them), Packet Logger mode (logs packets to disk), and Network Intrusion Detection System mode (analyzes traffic against a rule set and generates alerts). These are the foundational modes documented in Snort's official architecture.
Snort does not have a Host Intrusion Detection System mode - it is a network-based tool and does not operate at the host level natively.
Snort is not configured as a Host Intrusion Prevention System; it operates at the network level, and Packet Logger is the missing mode here.
Snort does not include a Host Intrusion Prevention System mode - its third mode is NIDS, not HIPS.
Concept tested: Snort IDS operational modes configuration
Source: https://www.snort.org/documents
Topics
Community Discussion
No community discussion yet for this question.