nerdexam
GIAC

GCFA · Question #262

John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking a

The correct answer is B. Snort D. Samhain. Snort and Samhain are both IDS tools capable of detecting intrusion attempts and generating security alerts, making them appropriate for testing an IDS deployment.

Threat Hunting & Timeline Analysis

Question

John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking attempts. Which of the following tools can John use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ASARA
  • BSnort
  • CTripwire
  • DSamhain

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    84% (16)
  • C
    5% (1)

Why each option

Snort and Samhain are both IDS tools capable of detecting intrusion attempts and generating security alerts, making them appropriate for testing an IDS deployment.

ASARA

SARA (Security Auditor's Research Assistant) is a network vulnerability scanner that identifies known vulnerabilities in systems - it does not function as an IDS and does not generate alerts about live hacking attempts.

BSnortCorrect

Snort is an open-source network-based intrusion detection and prevention system (NIDS) that inspects network traffic in real time and generates alerts for suspicious or malicious patterns, directly fulfilling the need to detect and alert on hacking attempts.

CTripwire

Tripwire is a file integrity monitoring solution that detects unauthorized changes to files and directories, but it is not designed to monitor network traffic or generate real-time intrusion alerts.

DSamhainCorrect

Samhain is an open-source host-based intrusion detection system (HIDS) that monitors file integrity, login activity, and system processes, generating alerts when unauthorized changes or access attempts are detected on a host.

Concept tested: Network and host-based IDS tool identification

Source: https://www.snort.org/documents

Topics

#IDS testing#Snort#Samhain#intrusion detection

Community Discussion

No community discussion yet for this question.

Full GCFA Practice