Certified Ethical Hacker CEH · Free Practice Question Medium
Question 8
Which of the following IDS is more relevant for a large environment having network segmentation for critical data?
- A A. Host based intrusion detection system (HIDS)
- B B. Network based intrusion detection system (NIDS)
- C C. Packet filtering firewall
- D D. Stateful inspection
Reveal correct answer
Correct answer: B
Explanation
Correct Answer: B. Network based intrusion detection system (NIDS) Explanation: A NIDS Monitor network traffic in real-time and can detect and alert on potential intrusion attempts across multiple hosts and network segments. This makes it particularly useful for large environments with complex network architectures and a need for centralized monitoring and control. On the other hand, a host-based intrusion detection system (HIDS) is typically deployed on individual hosts and can provide more detailed information about specific host-level events and activity. However, in a large environment with many hosts and network segments, deploying and managing HIDS across all hosts can be more difficult and time-consuming. Packet filtering firewalls and stateful inspection are also important security measures but are not intrusion detection systems per se. Packet filtering firewalls block or allow traffic based on predefined rules, while stateful inspection goes a step further by monitoring the state of network connections to identify and prevent suspicious activity. However, they may not provide the same level of granular visibility and detection capabilities as a NIDS.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
