EC-Council
EC0-350 · Question #218
When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?
The correct answer is B. Continues to evaluate the packet until all rules are checked. See the full explanation below for the reasoning.
Question
When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?
Options
- ADrops the packet and moves on to the next one
- BContinues to evaluate the packet until all rules are checked
- CStops checking rules, sends an alert, and lets the packet continue
- DBlocks the connection with the source IP address in the packet
How the community answered
(26 responses)- A12% (3)
- B77% (20)
- C8% (2)
- D4% (1)
Community Discussion
No community discussion yet for this question.