Click here for more: Scholars nexus
Enterprise - Exam 2 Questions with Detailed Verified
Answers
A process of grouping almost identical alarms that occur nearly at the same time into a single
higher-level alarm is known as alarm _____. Ans: ✓ ✓ ✓ clustering
A unique value or pattern of an attack that enables detection is called a(n) _____. Ans: ✓ ✓ ✓
signature
A ____ rootkit is one that becomes a part of the system bootstrap process and is loaded every time
the system boots. Ans: ✓ ✓ ✓ persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log files generated by servers,
network devices, and even other IDPSs. Ans: ✓ ✓ ✓ log file monitor
A(n) ____ is any system resource that is placed in a functional system but has no normal use in that
system. If it attracts attention, it is from unauthorized access and will trigger a notification or
response. Ans: ✓ ✓ ✓ honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the implementation and
operation of IDPSs within the organization. Ans: ✓ ✓ ✓ site policy
An advantage of an HIDPS is _____. Ans: ✓ ✓ ✓ it functions on the host system, where encrypted
traffic is decrypted and available for processing
By guarding against some types of vulnerabilities, an IDPS can become an important part of an
organization's _____ strategy. Ans: ✓ ✓ ✓ defense in depth
In an attack known as ____, valid protocol packets exploit poorly configured DNS servers to inject
false information and corrupt the servers' answers to routine DNS queries from other systems on
that network. Ans: ✓ ✓ ✓ DNS cache poisoning
Like the Wiretap Act's prohibition on intercepting the contents of communications, the _____
creates a general prohibition on the real-time monitoring of traffic data relating to communications.
Ans: ✓ ✓ ✓ Pen/Trap statute
© Get it right 2025 Getaway - Stuvia US All rights reserved
, Click here for more: Scholars nexus
The ongoing activity from alarm events that are accurate and noteworthy but not necessarily as
significant as potentially successful attacks is called ____. Ans: ✓ ✓ ✓ noise
The process of classifying the attack alerts that an IDPS detects in order to distinguish or sort false
positives from actual attacks more efficiently is known as alarm _____. Ans: ✓ ✓ ✓ filtering
The SIEM capability of _____ enables flexible and timely reaction to attacks Ans: ✓ ✓ ✓ real-time
monitoring
The SIEM capability of _____ enables review of system activity that can identify breaches and reveal
insider misuse. Ans: ✓ ✓ ✓ user monitoring
The use of IDPS sensors and analysis systems can be quite complex. One very common approach is
to use an open source software program called ____ running on a UNIX or Linux system that can be
managed and queried from a desktop computer using a client interface. Ans: ✓ ✓ ✓ Snort
The ____ of a switch or other networking device is a specially configured connection that is capable
of viewing all the traffic that moves through the entire device. Ans: ✓ ✓ ✓ monitoring port
The _____ resides on a particular computer or server, known as the host, and monitors activity only
on that system. Ans: ✓ ✓ ✓ HIDPS
Which is the most important factor when selecting a SIEM solution? Ans: ✓ ✓ ✓ The extent to
which the SIEM system provides the required features the organization needs.
____ are closely monitored network decoys that can distract adversaries from more valuable
machines on a network, provide early warning about new attack and exploitation trends; and can
allow in-depth examination of adversaries during and after exploitation. Ans: ✓ ✓ ✓ Honeypots
_____ is a value associated with an IDPS's ability to detect and identify an attack correctly. Ans: ✓
✓ ✓ Confidence
_____ systems use a combination of resources to detect an intrusion and then track it back to its
source; they must be used with caution to avoid illegal actions. Ans: ✓ ✓ ✓ Trap and trace
A ____ attack is much more substantial than a DoS attack because of the use of multiple systems to
simultaneously attack a single target. Ans: ✓ ✓ ✓ distributed denial-of-service
A ____ is a small quantity of data kept by a Web site as a means of recording that a system has
visited that Web site. Ans: ✓ ✓ ✓ cookie
© Get it right 2025 Getaway - Stuvia US All rights reserved
Enterprise - Exam 2 Questions with Detailed Verified
Answers
A process of grouping almost identical alarms that occur nearly at the same time into a single
higher-level alarm is known as alarm _____. Ans: ✓ ✓ ✓ clustering
A unique value or pattern of an attack that enables detection is called a(n) _____. Ans: ✓ ✓ ✓
signature
A ____ rootkit is one that becomes a part of the system bootstrap process and is loaded every time
the system boots. Ans: ✓ ✓ ✓ persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log files generated by servers,
network devices, and even other IDPSs. Ans: ✓ ✓ ✓ log file monitor
A(n) ____ is any system resource that is placed in a functional system but has no normal use in that
system. If it attracts attention, it is from unauthorized access and will trigger a notification or
response. Ans: ✓ ✓ ✓ honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the implementation and
operation of IDPSs within the organization. Ans: ✓ ✓ ✓ site policy
An advantage of an HIDPS is _____. Ans: ✓ ✓ ✓ it functions on the host system, where encrypted
traffic is decrypted and available for processing
By guarding against some types of vulnerabilities, an IDPS can become an important part of an
organization's _____ strategy. Ans: ✓ ✓ ✓ defense in depth
In an attack known as ____, valid protocol packets exploit poorly configured DNS servers to inject
false information and corrupt the servers' answers to routine DNS queries from other systems on
that network. Ans: ✓ ✓ ✓ DNS cache poisoning
Like the Wiretap Act's prohibition on intercepting the contents of communications, the _____
creates a general prohibition on the real-time monitoring of traffic data relating to communications.
Ans: ✓ ✓ ✓ Pen/Trap statute
© Get it right 2025 Getaway - Stuvia US All rights reserved
, Click here for more: Scholars nexus
The ongoing activity from alarm events that are accurate and noteworthy but not necessarily as
significant as potentially successful attacks is called ____. Ans: ✓ ✓ ✓ noise
The process of classifying the attack alerts that an IDPS detects in order to distinguish or sort false
positives from actual attacks more efficiently is known as alarm _____. Ans: ✓ ✓ ✓ filtering
The SIEM capability of _____ enables flexible and timely reaction to attacks Ans: ✓ ✓ ✓ real-time
monitoring
The SIEM capability of _____ enables review of system activity that can identify breaches and reveal
insider misuse. Ans: ✓ ✓ ✓ user monitoring
The use of IDPS sensors and analysis systems can be quite complex. One very common approach is
to use an open source software program called ____ running on a UNIX or Linux system that can be
managed and queried from a desktop computer using a client interface. Ans: ✓ ✓ ✓ Snort
The ____ of a switch or other networking device is a specially configured connection that is capable
of viewing all the traffic that moves through the entire device. Ans: ✓ ✓ ✓ monitoring port
The _____ resides on a particular computer or server, known as the host, and monitors activity only
on that system. Ans: ✓ ✓ ✓ HIDPS
Which is the most important factor when selecting a SIEM solution? Ans: ✓ ✓ ✓ The extent to
which the SIEM system provides the required features the organization needs.
____ are closely monitored network decoys that can distract adversaries from more valuable
machines on a network, provide early warning about new attack and exploitation trends; and can
allow in-depth examination of adversaries during and after exploitation. Ans: ✓ ✓ ✓ Honeypots
_____ is a value associated with an IDPS's ability to detect and identify an attack correctly. Ans: ✓
✓ ✓ Confidence
_____ systems use a combination of resources to detect an intrusion and then track it back to its
source; they must be used with caution to avoid illegal actions. Ans: ✓ ✓ ✓ Trap and trace
A ____ attack is much more substantial than a DoS attack because of the use of multiple systems to
simultaneously attack a single target. Ans: ✓ ✓ ✓ distributed denial-of-service
A ____ is a small quantity of data kept by a Web site as a means of recording that a system has
visited that Web site. Ans: ✓ ✓ ✓ cookie
© Get it right 2025 Getaway - Stuvia US All rights reserved