GCFA · Question #262
John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking a
The correct answer is B. Snort D. Samhain. Snort and Samhain are both IDS tools capable of detecting intrusion attempts and generating security alerts, making them appropriate for testing an IDS deployment.
Question
John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking attempts. Which of the following tools can John use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
Options
- ASARA
- BSnort
- CTripwire
- DSamhain
How the community answered
(19 responses)- A11% (2)
- B84% (16)
- C5% (1)
Why each option
Snort and Samhain are both IDS tools capable of detecting intrusion attempts and generating security alerts, making them appropriate for testing an IDS deployment.
SARA (Security Auditor's Research Assistant) is a network vulnerability scanner that identifies known vulnerabilities in systems - it does not function as an IDS and does not generate alerts about live hacking attempts.
Snort is an open-source network-based intrusion detection and prevention system (NIDS) that inspects network traffic in real time and generates alerts for suspicious or malicious patterns, directly fulfilling the need to detect and alert on hacking attempts.
Tripwire is a file integrity monitoring solution that detects unauthorized changes to files and directories, but it is not designed to monitor network traffic or generate real-time intrusion alerts.
Samhain is an open-source host-based intrusion detection system (HIDS) that monitors file integrity, login activity, and system processes, generating alerts when unauthorized changes or access attempts are detected on a host.
Concept tested: Network and host-based IDS tool identification
Source: https://www.snort.org/documents
Topics
Community Discussion
No community discussion yet for this question.