An _________ ___________ involves taking an action based on an attack or threat
A response generated in real time.
Active response
DLP
Data loss prevention
A physical and logical depiction of your network that includes methods, security, and technologies
Security topology
Is the raw information that the IDS or IPS uses to detect
suspicious activity.
Data Source
An ______ _________ can technically be used for either a wired or wireless connection, in reality the term is almost exclusively associated with a wireless-enabling device today.
AP
Access Point
Variations from normal operations.
Looks for things outside the ordinary
Anomalies
HIDS
A host-based intrusion detection system
One of the first lines of defense in a network
Firewalls
Is the component or process the operator uses to manage the IDS or IPS.
Manager
Detects and monitors the network for anomalies and detects and logs only
NIDS
This system works by looking for deviations from a pattern of normal network traffic.
Anomaly-detection IDS (AD-IDS)
NIDS
A network-based intrusion detection system. An NIPS is an intrusion prevention system. Unlike an HIDS/HIPS, an NIDS/NIPS scans an entire network
segment
Configurations in a router or firewall that determine what is allowed in (in terms of traffic, data, applications, or whatever other term for criteria you want to use) and what is left out
Access control lists (ACLs)
Type of detection that looks for variations in behavior
such as unusually high traffic, policy violations, and so on.
Behavior-Based Detection
Focuses on not only detecting anomalies on the network but focused on protecting the network as well
NIPS
A collection of computer networks that agree on standards of operation, such as security standards
Federation
IPSec
Internet Protocol Security
An all-in-one appliance,
Unified threat management
_________-________ __________is a system that acts based on the digital signature it sees and offers no repudiation to increase the integrity of a message.
Signature-Based Detection
You’ve been notified that you’ll soon be transferred to another site. Before you leave,
you’re to audit the network and document everything in use and the reason why it’s
in use. The next administrator will use this documentation to keep the network
running. Which of the following protocols isn’t a tunneling protocol but is probably
used at your site by tunneling protocols for network security?
A. IPSec
B. PPTP
C. L2TP
D. L2F
IPsec
______ _________ _________ __________- is an intrusion detection system that monitors the computer infrastructure on which it is installed, analyzing traffic and logging malicious behavior. An HIDS gives you deep visibility into what's happening on your critical security systems ...
Works to identify and log changes in the system.
Passive
HIDS
Host Intrusion Detection SystemSIEM
Security information and event management
a private network connection that occurs through a
public network
A virtual private network (VPN)
Which device stores information about destinations in a network (choose the best
answer)?
A. Hub
B. Modem
C. Firewall
D. Router
D. Router
Which of the following can be implemented as a software or hardware solution and is
usually associated with a device—a router, a firewall, NAT, and so on—used to shift a
load from one device to another?
A load balancer
An authentication protocol developed at MIT that uses tickets for authentication.
Kerberos
SSL
Secure Sockets Layer
The _______________ is the person responsible for setting the security policy for an organization and is responsible for making decisions about the deployment
and configuration of the IDS
Administrator
Upper management has suddenly become concerned about security. As the senior network administrator, you are asked to suggest changes that should be
implemented. Which of the following access methods should you recommend if the technique to be used is one that is primarily based on preestablished access and can’t be changed by users?
A. MAC
B. DAC
C. RBAC
D. Kerberos
A. MAC
Mandatory Access Control
involves blocking websites (or sections of websites) based solely on the URL, restricting access to specified websites and certain web-based applications
URL filtering
Unlike an HIDS/HIPS, an ____ ______ ______ _______ scans an entire network segment.
Passive
NIDS Network Intrusion Detection System
NAC
network access control
Is a message from the analyzer indicating that an event of interest has
occurred.
Alert
You’ve been assigned to mentor a junior administrator and bring her up to speed
quickly. The topic you’re currently explaining is authentication. Which method uses
a KDC to accomplish authentication for users, programs, or systems?
A. CHAP
B. Kerberos
C. Biometrics
D. Smartcards
Kerberos
Works by looking at the data that is coming in. Microsoft included content filtering in some versions of their browsers (Internet Explorer and Microsoft Edge), which could be configured using Content Advisor.
Content inspection
A tool that enumerates your network and provides a map of the network.
Network scanner
ACL
access control list
___________ __________also called packet sniffers, are some of the most common tools used
by network administrators.
Analyzer
Replaced SSL
TLS (Transport Layer Security)
Looks for variations in behavior such as unusually high traffic, policy violations, and so on
Behavior-Based Detection