nerdexam
(ISC)2

CSSLP · Question #198

Which of the following is an open source network intrusion detection system?

The correct answer is D. Snort. Snort is a widely recognized open-source network intrusion detection system (NIDS) capable of performing real-time traffic analysis and packet logging. It can detect a variety of attacks and probes by using rule-based signatures.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following is an open source network intrusion detection system?

Options

  • ANETSH
  • BMacof
  • CSourcefire
  • DSnort

How the community answered

(68 responses)
  • A
    1% (1)
  • B
    4% (3)
  • C
    3% (2)
  • D
    91% (62)

Why each option

Snort is a widely recognized open-source network intrusion detection system (NIDS) capable of performing real-time traffic analysis and packet logging. It can detect a variety of attacks and probes by using rule-based signatures.

ANETSH

NETSH is a command-line scripting utility in Windows for configuring network settings, not an intrusion detection system.

BMacof

Macof is a tool used for MAC flooding attacks, not for intrusion detection.

CSourcefire

Sourcefire was a company that developed security products, including commercial versions of Snort, but Snort itself is the open-source NIDS, not Sourcefire as a product.

DSnortCorrect

Snort is a well-known, free, and open-source network intrusion detection system (NIDS) that performs real-time traffic analysis, packet logging, and can detect various types of attacks.

Concept tested: Open-source Network Intrusion Detection Systems (NIDS)

Source: https://www.snort.org/

Topics

#NIDS#Open Source Security Tools#Snort#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice