D483 - IDS/IPS and SIEM exam Questions with Correct Answers
D483 - IDS/IPS and SIEM exam Questions with Correct Answers What is an IDS? An Intrusion Detection System; monitors network traffic or system activity for malicious behavior and alerts administrators. What is an IPS? An Intrusion Prevention System; detects and actively blocks or prevents malicious traffic from continuing. How does a signature-based IDS work? signatures or rule sets (e.g., Snort rules). What is anomaly-based detection in IDS/IPS? Matches traffic patterns against known attack Identifies deviations from a learned baseline of normal behavior to flag potential threats
Document information
- Uploaded on
- November 8, 2025
- Number of pages
- 3
- Written in
- 2025/2026
- Type
- Exam (elaborations)
- Contains
- Questions & answers