Question 1.1. (TCO 7) The type of IDS signature that triggers on a multiple packet stream is called _____. (Points : 3)




compound or composite

Question 2.2. (TCO 7) Which device responds immediately and does not allow malicious traffic to pass? (Points : 3)

Intrusion detections system (IDS)

Intrusion prevention system (IPS)

All of the above

Neither of the above

Question 3.3. (TCO 7) An IPS sensor that receives a copy of data for analysis while the original data continues toward the destination is running in _____ mode. (Points : 3)





Question 4.4. (TCO 7) Most IOS commands used to configure an intrusion prevention system (IPS) begin with the prefix _____.(Points : 3)

ids ips

ips ip

ip ips

ios ips

Question 5.5. (TCO 7) Which is an IDS or IPS signature? (Points : 3)

A message digest encrypted with the sender’s private key

A set of rules used to detect typical intrusive activity

A binary pattern specific to a virus

An appliance that provides anti-intrusion services

Question 6.6. (TCO 7) Which of the following ip actions will drop the packet and all future packets from this TCP flow? (Points : 3)

Deny attacker inline

Deny connection inline

Deny ip host inline

Deny packet inline

Question 7.7. (TCO 7) Which of the following are signature types that IOS firewall IDS can detect as requiring the storage of state information? (Points : 3)




Compound (composite)

Question 8.8. (TCO 7) Why is a network using IDS only more vulnerable to atomic attacks? (Points : 3)

IDS must track three-way handshakes of established TCP connections.

IDS cannot track UDP sessions.

IDS permits malicious single packets into a network.

IDS is not stateful and therefore cannot track multiple-packet attack streams.

