MCQs City stays free thanks to ads. Please turn off your ad blocker for this site so content and features keep working.
Computer Networks
Entrance Exams
Q
Which of the following is true of signature-based IDSes?
AA. They alert administrators to deviations from ?normal” traffic behavior
BB. They identify previously unknown attacks
CC. The technology is mature and reliable enough to use on production networks
DD. They scan network traffic or packets to identify matches with attack-definition files
Correct Answer:
D. D. They scan network traffic or packets to identify matches with attack-definition files
Explanation:
They are constantly updated with attack-definition files (signatures) that describe each type of known malicious activity. They then scan network traffic for packets that match the signatures, and then raise alerts to security administrators.