GSEC · Question #222
Which of the following is a signature-based intrusion detection system (IDS) ?
The correct answer is B. Snort. Snort is the most well-known open-source, signature-based IDS/IPS - it detects intrusions by matching network traffic against a database of known attack signatures. RealSecure (IBM ISS) also used signatures but is less commonly cited in certification contexts. StealthWatch…
Question
Which of the following is a signature-based intrusion detection system (IDS) ?
Options
- ARealSecure
- BSnort
- CStealthWatch
- DTripwire
How the community answered
(35 responses)- A9% (3)
- B83% (29)
- C3% (1)
- D6% (2)
Explanation
Snort is the most well-known open-source, signature-based IDS/IPS - it detects intrusions by matching network traffic against a database of known attack signatures. RealSecure (IBM ISS) also used signatures but is less commonly cited in certification contexts. StealthWatch (Cisco) is an anomaly/behavior-based network analysis tool, not signature-based. Tripwire is a file integrity monitoring tool that detects unauthorized changes to system files, not a network IDS. Snort is the canonical answer for signature-based IDS on certification exams.
Topics
Community Discussion
No community discussion yet for this question.