Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 3Objective 3

Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 5)

Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
7concepts

Questions 21–25

  1. 21application · medium

    A security analyst is evaluating an IDS for a network that frequently changes, with new applications and services added monthly. The analyst wants to detect zero-day attacks but is concerned about the administrative overhead of maintaining detection rules. Which detection method is most appropriate?

    Select an answer first
  2. 22foundation · easy

    Which detection method is most effective at identifying previously unknown attacks that deviate from normal behavior?

    Select an answer first
  3. 23application · medium

    After deploying an IPS, the security team notices that legitimate traffic is being blocked because the IPS flags normal application behavior as malicious. Which tuning action should be taken first?

    Select an answer first
  4. 24foundation · easy

    What is a false positive in the context of IDS/IPS?

    Select an answer first
  5. 25application · medium

    An attacker is using SSL/TLS encryption to hide malicious payloads from the network IDS. The security team wants to inspect the decrypted traffic. What is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.