SSCP · Question #352
Which of the following is used to monitor network traffic or to monitor host audit logs in real time to determine violations of system security policy that have taken place?
The correct answer is A. Intrusion Detection System. An Intrusion Detection System (IDS) is specifically designed to monitor network traffic and/or host audit logs in real time, alerting security teams when activity violates established security policies - exactly matching the question's description. Why the distractors are…
Question
Options
- AIntrusion Detection System
- BCompliance Validation System
- CIntrusion Management System (IMS)
- DCompliance Monitoring System
How the community answered
(31 responses)- A87% (27)
- B10% (3)
- D3% (1)
Explanation
An Intrusion Detection System (IDS) is specifically designed to monitor network traffic and/or host audit logs in real time, alerting security teams when activity violates established security policies - exactly matching the question's description.
Why the distractors are wrong:
- B. Compliance Validation System - not a standard security technology; "compliance validation" describes a process, not a real-time traffic monitoring tool.
- C. Intrusion Management System (IMS) - a fabricated term; no widely recognized security product category uses this name.
- D. Compliance Monitoring System - also not a recognized product category for real-time traffic/log analysis; compliance monitoring tools focus on regulatory adherence, not detecting security policy violations in live traffic.
Memory tip: Think of IDS as a silent alarm system for your network - just like a burglar alarm detects and alerts (but doesn't stop the intruder), an IDS watches traffic and logs and raises the alarm when something looks wrong. The key word in the question is "determine violations" - detection, not prevention (that would be an IPS).
Topics
Community Discussion
No community discussion yet for this question.