COMPUTER SECURITY FINAL EXAM
WITH VERIFIED ANSWERS
Intrusion |detection |is |based |on |the |assumption |that |the |behavior |of |the |intruder
|differs |from |that |of |a |legitimate |user |in |ways |that |can |be |quantified. |- |correct
|answers✔✔TRUE
A |________ |monitors |network |traffic |for |particular |network |segments |or |devices |and
|analyzes |network, |transport, |and |application |protocols |to |identify |suspicious
|activity. |- |correct |answers✔✔NETWORK-BASED |IDS
Intruders |typically |use |steps |from |a |common |attack |methodology. |- |correct
|answers✔✔TRUE
Running |a |packet |sniffer |on |a |workstation |to |capture |usernames |and |passwords |is
|an |example |of |intrusion. |- |correct |answers✔✔TRUE
Network-based |intrusion |detection |makes |use |of |signature |detection |and |anomaly
|detection. |- |correct |answers✔✔TRUE
A |(n) |__________ |is |a |hacker |with |minimal |technical |skill |who |primarily |uses |existing
|attack |toolkits. |- |correct |answers✔✔APPRENTICE
A |_________ |is |a |security |event |that |constitutes |a |security |incident |in |which |an
|intruder |gains |access |to |a |system |without |having |authorization |to |do |so. |- |correct
|answers✔✔SECURITY |INTRUSION
An |intruder |can |also |be |referred |to |as |a |hacker |or |cracker. |- |correct
|answers✔✔TRUE
Anomaly |detection |is |effective |against |misfeasors. |- |correct |answers✔✔FALSE
,The |IDS |component |responsible |for |collecting |data |is |the |user |interface. |- |correct
|answers✔✔FALSE
The |primary |purpose |of |an |IDS |is |to |detect |intrusions, |log |suspicious |events, |and
|send |alerts. |- |correct |answers✔✔TRUE
Activists |are |either |individuals |or |members |of |an |organized |crime |group |with |a |goal
|of |financial |reward. |- |correct |answers✔✔FALSE
A |_________ |monitors |the |characteristics |of |a |single |host |and |the |events |occurring
|within |that |host |for |suspicious |activity. |- |correct |answers✔✔HOST-BASED |IDS
An |inline |sensor |monitors |a |copy |of |network |traffic; |the |actual |traffic |does |not |pass
|through |the |device. |- |correct |answers✔✔FALSE
_________ |is |a |document |that |describes |the |application |level |protocol |for |exchanging
|data |between |intrusion |detection |entities. |RFC |4767 |- |correct |answers✔✔RFC |4767
The |rule |_______ |tells |Snort |what |to |do |when |it |finds |a |packet |that |matches |the |rule
|criteria. |- |correct |answers✔✔ACTION
To |be |of |practical |use |an |IDS |should |detect |a |substantial |percentage |of |intrusions
|while |keeping |the |false |alarm |rate |at |an |acceptable |level. |- |correct |answers✔✔TRUE
A |common |location |for |a |NIDS |sensor |is |just |inside |the |external |firewall. |- |correct
|answers✔✔TRUE
A(n) |________ |event |is |an |alert |that |is |generated |when |the |gossip |traffic |enables |a
|platform |to |conclude |that |an |attack |is |under |way. |- |correct |answers✔✔DDI
, The |purpose |of |the |________ |module |is |to |collect |data |on |security |related |events |on
|the |host |and |transmit |these |to |the |central |manager. |- |correct |answers✔✔HOST
|AGENT
Signature-based |approaches |attempt |to |define |normal, |or |expected, |behavior,
|whereas |anomaly |approaches |attempt |to |define |proper |behavior. |- |correct
|answers✔✔FALSE
The |_________ |module |analyzes |LAN |traffic |and |reports |the |results |to |the |central
|manager. |- |correct |answers✔✔LAN |MONITOR |AGENT
Those |who |hack |into |computers |do |so |for |the |thrill |of |it |or |for |status. |- |correct
|answers✔✔TRUE
The |_______ |is |the |ID |component |that |analyzes |the |data |collected |by |the |sensor |for
|signs |of |unauthorized |or |undesired |activity |or |for |events |that |might |be |of |interest |to
|the |security |administrator. |- |correct |answers✔✔ANALYZER
Snort |can |perform |intrusion |prevention |but |not |intrusion |detection. |- |correct
|answers✔✔FALSE
The |________ |is |responsible |for |determining |if |an |intrusion |has |occurred. |- |correct
|answers✔✔ANALYZER
________ |are |either |individuals |or |members |of |a |larger |group |of |outsider |attackers
|who |are |motivated |by |social |or |political |causes. |- |correct |answers✔✔ACTIVISTS
__________ |involves |an |attempt |to |define |a |set |of |rules |or |attack |patterns |that |can |be
|used |to |decide |if |a |given |behavior |is |that |of |an |intruder. |- |correct
|answers✔✔SIGNATURE |DETECTION
_________ |involves |the |collection |of |data |relating |to |the |behavior |of |legitimate |users
|over |a |period |of |time. |- |correct |answers✔✔ANOMALY |DETECTION
WITH VERIFIED ANSWERS
Intrusion |detection |is |based |on |the |assumption |that |the |behavior |of |the |intruder
|differs |from |that |of |a |legitimate |user |in |ways |that |can |be |quantified. |- |correct
|answers✔✔TRUE
A |________ |monitors |network |traffic |for |particular |network |segments |or |devices |and
|analyzes |network, |transport, |and |application |protocols |to |identify |suspicious
|activity. |- |correct |answers✔✔NETWORK-BASED |IDS
Intruders |typically |use |steps |from |a |common |attack |methodology. |- |correct
|answers✔✔TRUE
Running |a |packet |sniffer |on |a |workstation |to |capture |usernames |and |passwords |is
|an |example |of |intrusion. |- |correct |answers✔✔TRUE
Network-based |intrusion |detection |makes |use |of |signature |detection |and |anomaly
|detection. |- |correct |answers✔✔TRUE
A |(n) |__________ |is |a |hacker |with |minimal |technical |skill |who |primarily |uses |existing
|attack |toolkits. |- |correct |answers✔✔APPRENTICE
A |_________ |is |a |security |event |that |constitutes |a |security |incident |in |which |an
|intruder |gains |access |to |a |system |without |having |authorization |to |do |so. |- |correct
|answers✔✔SECURITY |INTRUSION
An |intruder |can |also |be |referred |to |as |a |hacker |or |cracker. |- |correct
|answers✔✔TRUE
Anomaly |detection |is |effective |against |misfeasors. |- |correct |answers✔✔FALSE
,The |IDS |component |responsible |for |collecting |data |is |the |user |interface. |- |correct
|answers✔✔FALSE
The |primary |purpose |of |an |IDS |is |to |detect |intrusions, |log |suspicious |events, |and
|send |alerts. |- |correct |answers✔✔TRUE
Activists |are |either |individuals |or |members |of |an |organized |crime |group |with |a |goal
|of |financial |reward. |- |correct |answers✔✔FALSE
A |_________ |monitors |the |characteristics |of |a |single |host |and |the |events |occurring
|within |that |host |for |suspicious |activity. |- |correct |answers✔✔HOST-BASED |IDS
An |inline |sensor |monitors |a |copy |of |network |traffic; |the |actual |traffic |does |not |pass
|through |the |device. |- |correct |answers✔✔FALSE
_________ |is |a |document |that |describes |the |application |level |protocol |for |exchanging
|data |between |intrusion |detection |entities. |RFC |4767 |- |correct |answers✔✔RFC |4767
The |rule |_______ |tells |Snort |what |to |do |when |it |finds |a |packet |that |matches |the |rule
|criteria. |- |correct |answers✔✔ACTION
To |be |of |practical |use |an |IDS |should |detect |a |substantial |percentage |of |intrusions
|while |keeping |the |false |alarm |rate |at |an |acceptable |level. |- |correct |answers✔✔TRUE
A |common |location |for |a |NIDS |sensor |is |just |inside |the |external |firewall. |- |correct
|answers✔✔TRUE
A(n) |________ |event |is |an |alert |that |is |generated |when |the |gossip |traffic |enables |a
|platform |to |conclude |that |an |attack |is |under |way. |- |correct |answers✔✔DDI
, The |purpose |of |the |________ |module |is |to |collect |data |on |security |related |events |on
|the |host |and |transmit |these |to |the |central |manager. |- |correct |answers✔✔HOST
|AGENT
Signature-based |approaches |attempt |to |define |normal, |or |expected, |behavior,
|whereas |anomaly |approaches |attempt |to |define |proper |behavior. |- |correct
|answers✔✔FALSE
The |_________ |module |analyzes |LAN |traffic |and |reports |the |results |to |the |central
|manager. |- |correct |answers✔✔LAN |MONITOR |AGENT
Those |who |hack |into |computers |do |so |for |the |thrill |of |it |or |for |status. |- |correct
|answers✔✔TRUE
The |_______ |is |the |ID |component |that |analyzes |the |data |collected |by |the |sensor |for
|signs |of |unauthorized |or |undesired |activity |or |for |events |that |might |be |of |interest |to
|the |security |administrator. |- |correct |answers✔✔ANALYZER
Snort |can |perform |intrusion |prevention |but |not |intrusion |detection. |- |correct
|answers✔✔FALSE
The |________ |is |responsible |for |determining |if |an |intrusion |has |occurred. |- |correct
|answers✔✔ANALYZER
________ |are |either |individuals |or |members |of |a |larger |group |of |outsider |attackers
|who |are |motivated |by |social |or |political |causes. |- |correct |answers✔✔ACTIVISTS
__________ |involves |an |attempt |to |define |a |set |of |rules |or |attack |patterns |that |can |be
|used |to |decide |if |a |given |behavior |is |that |of |an |intruder. |- |correct
|answers✔✔SIGNATURE |DETECTION
_________ |involves |the |collection |of |data |relating |to |the |behavior |of |legitimate |users
|over |a |period |of |time. |- |correct |answers✔✔ANOMALY |DETECTION