Which of the following NIDS configurations is based solely on specific network traffic?
  1. Anomaly based
  2. Behavior based
  3. Signature based
  4. Passive IDS
Explanation
Answer: D - A signature based NIDS is solely based on specific network traffic.

Key Takeaway: IDS is primarily focused on evaluating attacks based on attack signatures and audit trails. A signature based intrusion detection system, or IDS, evaluates packets on the network to a database of known attacks for similarities to these known attacks. The issue that can occur with a signature based IDS is the lag time between the exploits being released and the database being updated with the signature. An anomaly or behavior based IDS is one that looks for behaviors different than expected based on the system’s configuration.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz