Soru

Zorluk: OrtaIntrusion Detection and Prevention Systems (IDS/IPS)

A security administrator needs to detect malicious process injections and file modifications on an internal application server that processes encrypted HTTPS traffic. The solution must inspect activity post-decryption without introducing network transmission latency or requiring payload decryption keys on network taps. Which detection system and deployment strategy best meets these requirements?

  1. Host-based Intrusion Detection System (HIDS) installed directly on the application server operating systemCevap
  2. B
    Passive Network Intrusion Detection System (NIDS) monitoring port 443 traffic via a network switch SPAN port
  3. C
    Inline Network Intrusion Prevention System (NIPS) reconfigured to inspect Layer 3 IP frame headers for host memory anomalies
  4. D
    Stateless router Access Control List (ACL) with standard implicit deny rules deployed at the subnet gateway

Cevap

Host-based Intrusion Detection System (HIDS) installed directly on the application server operating system
The Host-based Intrusion Detection System (HIDS) option is correct because HIDS agents run locally on the target operating system. This provides full visibility into system calls, process memory, local file modifications, and decrypted application payloads without altering or adding latency to network packet routing.

Adım Adım Çözüm

1
Analyze the operational constraints and inspection requirements
The requirements demand inspecting activity after TLS decryption, monitoring system processes/files, and introducing zero network latency.
Network-based systems inspecting wire traffic cannot view encrypted TLS payloads without out-of-band decryption architectures.
2
Evaluate host-based versus network-based security controls
Host-based Intrusion Detection Systems (HIDS) reside on the endpoint OS and have direct visibility into unencrypted data, local process execution, and system files.
Because HIDS runs on the host itself, packet transmission across network interfaces is unaffected, avoiding network latency.

Anahtar Kavram

HIDS vs NIDS/NIPS Deployment & Visibility Scope
Tahmini Süre:1m 15s
Bu soruyu puanla