Network Security and Scanning Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security and Scanning flashcards as text
What is the primary function of an Intrusion Detection System (IDS)?
Answer: To monitor traffic and alert on suspicious activity
An IDS monitors network or host activity and raises alerts on suspicious or malicious patterns.
How does a signature-based IDS detect attacks?
Answer: By matching traffic against a database of known attack patterns
Signature-based IDS compares traffic to a database of known malicious patterns or signatures.
Which evasion technique splits a malicious payload across multiple packets?
Answer: Fragmentation
Fragmentation breaks the payload across packets so an IDS may fail to reassemble and detect it.
What distinguishes an IPS from an IDS?
Answer: An IPS can actively block or drop malicious traffic
An IPS is inline and can actively block or drop malicious traffic, while an IDS only detects and alerts.
A honeypot is best described as what?
Answer: A decoy system designed to attract and study attackers
A honeypot is a deliberately vulnerable decoy used to lure, detect, and analyze attackers.
Which technique can be used to evade signature-based detection during a scan?
Answer: Encoding or obfuscating the payload
Encoding or obfuscating payloads changes their signature so known patterns no longer match.
What is the purpose of a DMZ in network architecture?
Answer: To isolate public-facing servers from the internal network
A DMZ places public-facing servers in a segmented zone to limit exposure of the internal network.