Exam 4: Incident Response: Detection and Decision Making

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

What are honeypots? Briefly describe each of the two general types.

(Essay)
4.8/5
(29)

The term ____ refers to the level at which the IDS triggers an alert to notify the administrator.

(Multiple Choice)
4.7/5
(30)

The Electronic Communications Protection Act prohibits the recording of wire- or cable-based communications unless an exception applies.Briefly discuss four of these exceptions.

(Essay)
4.9/5
(33)

A ____ is a high-interaction honeypot designed to capture extensive information on threats.

(Multiple Choice)
4.9/5
(31)

Match each statement with an item below. -Triggers an alert or alarm when one of the following changes occurs: file attributes change,new files are created,or existing files are deleted.

(Multiple Choice)
4.9/5
(30)

____ is an IDS's ability to dynamically modify its site policies in reaction or response to environmental activity.

(Multiple Choice)
4.8/5
(31)

What are the advantages and disadvantages of NIDS?

(Essay)
4.9/5
(38)

_________________________ is the process of evaluating circumstances around organizational events,determining which events are possible incidents,or incident candidates,and then determining whether or not the event constitutes an actual incident.

(Short Answer)
4.8/5
(41)

A ____ is a type of IDS that is similar to the NIDS,reviews the log files generated by servers,network devices,and even other IDSs.

(Multiple Choice)
4.8/5
(31)
Showing 41 - 49 of 49
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)