
EC-CouncilNetwork Defense Essentials
Domain 3Objective 3
Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 4)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
7concepts
Questions 16–20
- 16
A security administrator is configuring an inline IPS for a web server farm. The team is concerned about false positives blocking legitimate customer traffic. Which response action should be configured as the initial setting to balance security and availability?
Select an answer first - 17
Which type of IDS/IPS is best suited to monitor traffic on a wireless network segment?
Select an answer first - 18
What is a common countermeasure against evasion techniques like fragmentation and packet splitting?
Select an answer first - 19
A security team is configuring an IPS for a critical database server. The server handles transactions that must not be interrupted. The team wants to block attacks but is concerned about false positives causing downtime. Which response strategy best balances security and availability?
Select an answer first - 20
A company wants to detect rogue wireless access points that are being plugged into the wired network by employees. The security team already has a network-based IDS monitoring the wired backbone. What additional control is most effective for this specific threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.