CAS-001 · Question #448
A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can…
The correct answer is D. HIDS E. Port scanner. Detecting an insider or physical intruder who has connected to the network requires tools that identify unauthorized hosts and suspicious host-level activity. A Host-based Intrusion Detection System (HIDS) (D) monitors individual endpoints for signs of compromise or…
Question
A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can the network administrator use to scan and detect the presence of a malicious actor physically accessing the company's network or information systems from within? (Select TWO).
Options
- ARAS
- BVulnerability scanner
- CHTTP intercept
- DHIDS
- EPort scanner
- FProtocol analyzer
How the community answered
(18 responses)- A17% (3)
- B6% (1)
- C6% (1)
- D72% (13)
Explanation
Detecting an insider or physical intruder who has connected to the network requires tools that identify unauthorized hosts and suspicious host-level activity. A Host-based Intrusion Detection System (HIDS) (D) monitors individual endpoints for signs of compromise or unauthorized activity - file changes, unexpected processes, suspicious logins - that would indicate someone has gained unauthorized physical access to a machine. A port scanner (E) can be used to actively scan the network for unexpected or new devices that have been physically connected (e.g., a rogue laptop or network tap), revealing unauthorized hosts by their open ports and IP addresses. RAS (A) is a remote access service, not a detection tool. A vulnerability scanner (B) identifies weaknesses but is not designed to detect unauthorized presence in real time. HTTP intercept (C) monitors web traffic, not physical network intrusions. A protocol analyzer (F) captures traffic for analysis but is passive and not suited for scanning to detect unauthorized devices.
Topics
Community Discussion
No community discussion yet for this question.