
EC-CouncilNetwork Defense Essentials
Domain 3Objective 3
Intrusion Detection and Prevention Systems (IDS/IPS) NDE Practice Questions (Page 8)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
7concepts
Questions 36–40
- 36
Which response action is commonly taken by an IPS to terminate an active malicious session?
Select an answer first - 37
A security analyst needs to monitor the activities of a single critical server, including file integrity and process behavior. Which type of IDS/IPS is most appropriate?
Select an answer first - 38
An IPS has been detecting a high number of false positives for a legitimate application that uses unusual network behavior. The security team wants to maintain protection against real attacks but reduce the noise. Which action is the most appropriate first step?
Select an answer first - 39
A company wants to monitor all traffic entering and leaving its corporate network. The security team needs to see both inbound and outbound traffic, but the existing firewall is already a bottleneck. Which IDS/IPS placement provides visibility without adding inline latency?
Select an answer first - 40
Which statement best describes the role of an intrusion prevention system (IPS) in network security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.