Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 3Objective 3

Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 2)

Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
7concepts

Questions 6–10

  1. 6expert · hard

    An attacker is using a combination of packet fragmentation and TCP segmentation to evade a network-based IDS. The IDS is deployed inline and has stream reassembly enabled. However, the attacker is also using a technique that causes the IDS and the target server to reassemble packets differently. What is the most effective countermeasure?

    Select an answer first
  2. 7application · medium

    A security administrator is tuning an inline IPS that has been generating a high volume of alerts for legitimate peer-to-peer backup traffic. The IPS is currently configured to reset connections for any traffic matching a broad signature. The administrator wants to reduce false positives while still blocking the actual malware that uses similar traffic patterns. What is the most appropriate action?

    Select an answer first
  3. 8expert · hard

    A security analyst is comparing two IDS solutions for a network that experiences frequent legitimate protocol variations. Solution A uses signature-based detection and has a low false-positive rate. Solution B uses anomaly-based detection and has a high false-positive rate but can detect zero-day attacks. The team wants to minimize false positives while still detecting unknown threats. Which approach is most effective?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of an intrusion detection system (IDS) in network security?

    Select an answer first
  5. 10expert · hard

    A security team is troubleshooting why their network IDS is not detecting a known exploit. The exploit uses a technique where the attacker sends the payload in small, out-of-order TCP segments. The IDS is configured with signature-based detection and is placed passively on a SPAN port. Which configuration change is most likely to enable detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.