nerdexam
EC-Council

EC0-350 · Question #218

When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?

The correct answer is B. Continues to evaluate the packet until all rules are checked. See the full explanation below for the reasoning.

Question

When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?

Options

  • ADrops the packet and moves on to the next one
  • BContinues to evaluate the packet until all rules are checked
  • CStops checking rules, sends an alert, and lets the packet continue
  • DBlocks the connection with the source IP address in the packet

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    77% (20)
  • C
    8% (2)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice