
EC-CouncilNetwork Defense Essentials
Domain 3Objective 3
Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 6)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
7concepts
Questions 26–30
- 26
A security analyst is configuring an IDS for a network that must comply with a policy that only allows specific applications to run. The team wants to detect any violation of this policy. Which detection method is most appropriate?
Select an answer first - 27
A company wants to detect and block malicious traffic at the network perimeter. They also need to maintain a log of all detected threats for compliance. Which solution should they implement?
Select an answer first - 28
Which technique is commonly used by attackers to evade signature-based IDS by altering the payload to avoid matching known patterns?
Select an answer first - 29
A hospital's security team needs to detect unauthorized devices connecting to the clinical Wi-Fi network and prevent them from communicating with medical devices. Which type of IDS/IPS is best suited for this requirement?
Select an answer first - 30
A security administrator is tuning an anomaly-based IDS in a university network. The network has very predictable traffic during the semester but becomes almost idle during breaks. The administrator notices that the IDS generates many false positives at the start of each semester when students return. What is the best way to reduce these false positives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.