GSLC · Question #545
John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking…
The correct answer is B. Snort D. Samhain. This question identifies tools that function as intrusion detection systems (IDS) capable of generating alerts about hacking attempts on a target server.
Question
John works as a Network Security Professional. He is assigned a project to test the security of Intrusion Detection System on the We-are-secure server so that he can receive alerts about any hacking attempts. Which of the following tools can John use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
Options
- ASARA
- BSnort
- CTripwire
- DSamhain
How the community answered
(35 responses)- A6% (2)
- B91% (32)
- C3% (1)
Why each option
This question identifies tools that function as intrusion detection systems (IDS) capable of generating alerts about hacking attempts on a target server.
SARA (Security Auditor's Research Assistant) is a network vulnerability scanning tool used to identify weaknesses in systems, not an IDS that generates real-time alerts about active hacking attempts.
Snort is an open-source network-based intrusion detection and prevention system (NIDS/NIPS) that performs real-time traffic analysis and packet logging, generating alerts when traffic matches known attack signatures - making it directly suitable for monitoring a server for hacking attempts.
Tripwire is primarily a file integrity monitoring tool that detects unauthorized changes to files after the fact, and is not designed as a full-featured IDS for generating real-time hacking attempt alerts.
Samhain is a host-based intrusion detection system (HIDS) that monitors file integrity, detects rootkits, and generates security alerts for unauthorized changes or suspicious activity on a host, fulfilling the requirement to receive alerts about hacking attempts.
Concept tested: Identifying network and host-based IDS tools
Source: https://www.snort.org/documents
Topics
Community Discussion
No community discussion yet for this question.