
EC-CouncilNetwork Defense Essentials
Domain 3Objective 3
Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 5)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
7concepts
Questions 21–25
- 21
A security analyst is evaluating an IDS for a network that frequently changes, with new applications and services added monthly. The analyst wants to detect zero-day attacks but is concerned about the administrative overhead of maintaining detection rules. Which detection method is most appropriate?
Select an answer first - 22
Which detection method is most effective at identifying previously unknown attacks that deviate from normal behavior?
Select an answer first - 23
After deploying an IPS, the security team notices that legitimate traffic is being blocked because the IPS flags normal application behavior as malicious. Which tuning action should be taken first?
Select an answer first - 24
What is a false positive in the context of IDS/IPS?
Select an answer first - 25
An attacker is using SSL/TLS encryption to hide malicious payloads from the network IDS. The security team wants to inspect the decrypted traffic. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.