nerdexam
GIAC

GSEC · Question #222

Which of the following is a signature-based intrusion detection system (IDS) ?

The correct answer is B. Snort. Snort is the most well-known open-source, signature-based IDS/IPS - it detects intrusions by matching network traffic against a database of known attack signatures. RealSecure (IBM ISS) also used signatures but is less commonly cited in certification contexts. StealthWatch…

Network Security

Question

Which of the following is a signature-based intrusion detection system (IDS) ?

Options

  • ARealSecure
  • BSnort
  • CStealthWatch
  • DTripwire

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    83% (29)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Snort is the most well-known open-source, signature-based IDS/IPS - it detects intrusions by matching network traffic against a database of known attack signatures. RealSecure (IBM ISS) also used signatures but is less commonly cited in certification contexts. StealthWatch (Cisco) is an anomaly/behavior-based network analysis tool, not signature-based. Tripwire is a file integrity monitoring tool that detects unauthorized changes to system files, not a network IDS. Snort is the canonical answer for signature-based IDS on certification exams.

Topics

#IDS#Snort#signature-based detection#intrusion detection

Community Discussion

No community discussion yet for this question.

Full GSEC Practice