ENTERPRISE - EXAM 2 2025/2026
QUESTIONS AND ANSWERS 100% PASS
A process of grouping almost identical alarms that occur nearly at the same time into a single
higher-level alarm is known as alarm _____. - ANS clustering
A unique value or pattern of an attack that enables detection is called a(n) _____. -
ANS signature
A ____ rootkit is one that becomes a part of the system bootstrap process and is loaded every
time the system boots. - ANS persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log files generated by
servers, network devices, and even other IDPSs. - ANS log file monitor
A(n) ____ is any system resource that is placed in a functional system but has no normal use in
that system. If it attracts attention, it is from unauthorized access and will trigger a notification
or response. - ANS honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the implementation and
operation of IDPSs within the organization. - ANS site policy
An advantage of an HIDPS is _____. - ANS it functions on the host system, where encrypted
traffic is decrypted and available for processing
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, By guarding against some types of vulnerabilities, an IDPS can become an important part of an
organization's _____ strategy. - ANS defense in depth
In an attack known as ____, valid protocol packets exploit poorly configured DNS servers to
inject false information and corrupt the servers' answers to routine DNS queries from other
systems on that network. - ANS DNS cache poisoning
Like the Wiretap Act's prohibition on intercepting the contents of communications, the _____
creates a general prohibition on the real-time monitoring of traffic data relating to
communications. - ANS Pen/Trap statute
The ongoing activity from alarm events that are accurate and noteworthy but not necessarily as
significant as potentially successful attacks is called ____. - ANS noise
The process of classifying the attack alerts that an IDPS detects in order to distinguish or sort
false positives from actual attacks more efficiently is known as alarm _____. - ANS filtering
The SIEM capability of _____ enables flexible and timely reaction to attacks - ANS real-time
monitoring
The SIEM capability of _____ enables review of system activity that can identify breaches and
reveal insider misuse. - ANS user monitoring
The use of IDPS sensors and analysis systems can be quite complex. One very common
approach is to use an open source software program called ____ running on a UNIX or Linux
system that can be managed and queried from a desktop computer using a client interface. -
ANS Snort
The ____ of a switch or other networking device is a specially configured connection that is
capable of viewing all the traffic that moves through the entire device. - ANS monitoring port
The _____ resides on a particular computer or server, known as the host, and monitors activity
only on that system. - ANS HIDPS
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
QUESTIONS AND ANSWERS 100% PASS
A process of grouping almost identical alarms that occur nearly at the same time into a single
higher-level alarm is known as alarm _____. - ANS clustering
A unique value or pattern of an attack that enables detection is called a(n) _____. -
ANS signature
A ____ rootkit is one that becomes a part of the system bootstrap process and is loaded every
time the system boots. - ANS persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log files generated by
servers, network devices, and even other IDPSs. - ANS log file monitor
A(n) ____ is any system resource that is placed in a functional system but has no normal use in
that system. If it attracts attention, it is from unauthorized access and will trigger a notification
or response. - ANS honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the implementation and
operation of IDPSs within the organization. - ANS site policy
An advantage of an HIDPS is _____. - ANS it functions on the host system, where encrypted
traffic is decrypted and available for processing
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, By guarding against some types of vulnerabilities, an IDPS can become an important part of an
organization's _____ strategy. - ANS defense in depth
In an attack known as ____, valid protocol packets exploit poorly configured DNS servers to
inject false information and corrupt the servers' answers to routine DNS queries from other
systems on that network. - ANS DNS cache poisoning
Like the Wiretap Act's prohibition on intercepting the contents of communications, the _____
creates a general prohibition on the real-time monitoring of traffic data relating to
communications. - ANS Pen/Trap statute
The ongoing activity from alarm events that are accurate and noteworthy but not necessarily as
significant as potentially successful attacks is called ____. - ANS noise
The process of classifying the attack alerts that an IDPS detects in order to distinguish or sort
false positives from actual attacks more efficiently is known as alarm _____. - ANS filtering
The SIEM capability of _____ enables flexible and timely reaction to attacks - ANS real-time
monitoring
The SIEM capability of _____ enables review of system activity that can identify breaches and
reveal insider misuse. - ANS user monitoring
The use of IDPS sensors and analysis systems can be quite complex. One very common
approach is to use an open source software program called ____ running on a UNIX or Linux
system that can be managed and queried from a desktop computer using a client interface. -
ANS Snort
The ____ of a switch or other networking device is a specially configured connection that is
capable of viewing all the traffic that moves through the entire device. - ANS monitoring port
The _____ resides on a particular computer or server, known as the host, and monitors activity
only on that system. - ANS HIDPS
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED