nerdexam
GIAC

GCIA · Question #90

An IDS is a group of processes working together in a network. These processes work on different computers and devices across the network. Which of the following processes does an IDS perform? Each cor

The correct answer is A. Network traffic analysis B. Event log analysis C. Monitoring and analysis of user and system activity D. Statistical analysis of abnormal traffic patterns. This question covers the full scope of functions an IDS performs across a distributed network, confirming that all four listed activities are core IDS responsibilities.

Intrusion Detection System (IDS) Fundamentals & Snort Rules

Question

An IDS is a group of processes working together in a network. These processes work on different computers and devices across the network. Which of the following processes does an IDS perform? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ANetwork traffic analysis
  • BEvent log analysis
  • CMonitoring and analysis of user and system activity
  • DStatistical analysis of abnormal traffic patterns

How the community answered

(20 responses)
  • A
    100% (20)

Why each option

This question covers the full scope of functions an IDS performs across a distributed network, confirming that all four listed activities are core IDS responsibilities.

ANetwork traffic analysisCorrect

Network traffic analysis is a primary IDS function, allowing it to inspect packets for malicious signatures or anomalies.

BEvent log analysisCorrect

Event log analysis enables an IDS to correlate system and application log entries to identify suspicious sequences of events.

CMonitoring and analysis of user and system activityCorrect

Monitoring user and system activity allows the IDS to detect insider threats and abnormal process behavior.

DStatistical analysis of abnormal traffic patternsCorrect

Statistical analysis of abnormal traffic patterns is used in anomaly-based IDS to flag deviations from established baselines.

Concept tested: IDS core functions and distributed detection capabilities

Source: https://www.cisco.com/c/en/us/td/docs/security/ips/6-2/configuration/guide/IMC/imcguide/imcIDS.html

Topics

#IDS components#traffic analysis#anomaly detection#event log analysis

Community Discussion

No community discussion yet for this question.

Full GCIA Practice