nerdexam
CompTIA

N10-005 · Question #940

Which of the following security appliances would be used to only analyze traffic and send alerts when predefined patterns of unauthorized traffic are detected on the network?

The correct answer is C. Signature based IDS. An IDS (Intrusion Detection System) is a passive monitoring device - it analyzes traffic and generates alerts but does NOT actively block traffic. A signature-based IDS specifically compares traffic against a database of known attack patterns (signatures) to identify threats…

Network security

Question

Which of the following security appliances would be used to only analyze traffic and send alerts when predefined patterns of unauthorized traffic are detected on the network?

Options

  • AHost based IPS
  • BNetwork based firewall
  • CSignature based IDS
  • DBehavior based IPS

How the community answered

(23 responses)
  • B
    4% (1)
  • C
    91% (21)
  • D
    4% (1)

Explanation

An IDS (Intrusion Detection System) is a passive monitoring device - it analyzes traffic and generates alerts but does NOT actively block traffic. A signature-based IDS specifically compares traffic against a database of known attack patterns (signatures) to identify threats. An IPS (Intrusion Prevention System) actively blocks detected threats, which eliminates the host-based IPS and behavior-based IPS options. A network-based firewall enforces access control rules but doesn't focus on signature pattern detection and alerting. The key distinguishing words in the question are 'only analyze' and 'send alerts,' which point exclusively to IDS.

Topics

#IDS#signature-based detection#intrusion detection#network monitoring

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice