N10-005 · Question #196
A system administrator is implementing an IDS on the database server to see who is trying to access the server. The administrator relies on the software provider for what to detect. Which of the…
The correct answer is C. Signature based IDS. Signature detection involves searching network traffic for a series of bytes or packet sequences known to be malicious. A key advantage of this detection method is that signatures are easy to develop and understand if you know what network behavior you're trying to identify.
Question
A system administrator is implementing an IDS on the database server to see who is trying to access the server. The administrator relies on the software provider for what to detect. Which of the following would MOST likely be installed?
Options
- ABehavior based IDS
- BNetwork based IDS
- CSignature based IDS
- DHoneypot
How the community answered
(48 responses)- A2% (1)
- C94% (45)
- D4% (2)
Explanation
Signature detection involves searching network traffic for a series of bytes or packet sequences known to be malicious. A key advantage of this detection method is that signatures are easy to develop and understand if you know what network behavior you're trying to identify.
Topics
Community Discussion
No community discussion yet for this question.