Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 3Objective 3

Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 7)

Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
7concepts

Questions 31–35

  1. 31application · medium

    An attacker is attempting to evade a network-based IDS by sending a malicious payload split across many small packets that the IDS does not reassemble. The IDS is deployed passively on a SPAN port. Which countermeasure would be most effective against this fragmentation-based evasion?

    Select an answer first
  2. 32foundation · easy

    What is the primary difference between an alert and a block action in an IPS?

    Select an answer first
  3. 33application · medium

    An attacker is evading a network-based IDS by encoding the payload in a way that the IDS does not decode, while the target server does. Which countermeasure is most effective?

    Select an answer first
  4. 34application · medium

    A security administrator is deploying an IPS in a data center with high-throughput links. The administrator is concerned about the IPS becoming a bottleneck. Which factor is most important to consider during the deployment?

    Select an answer first
  5. 35application · medium

    An attacker is sending a known exploit payload but fragments it across multiple TCP segments to evade detection. The security team notices the IDS is not generating alerts for the attack. Which detection capability is most likely missing from the IDS configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.