Soru

Zorluk: KolayIntrusion Detection and Prevention Systems (IDS/IPS)

Match each Intrusion Detection and Prevention System (IDS/IPS) detection logic or deployment mode on the left with its corresponding operational description on the right.

  • Signature-based DetectionCompares inspected network traffic against a database of known attack patterns and exploit signatures.
  • Anomaly-based DetectionEstablishes a baseline of normal network behavior and triggers alerts when abnormal activity occurs.
  • Inline (In-band) DeploymentPlaced directly in the traffic flow to actively drop or terminate malicious connections in real time.
  • Passive (Out-of-band) DeploymentMonitors mirrored network traffic from a TAP or SPAN port without adding latency to the primary data path.

Cevap

Signature-based Detection matches known attack pattern databases; Anomaly-based Detection matches baseline deviation monitoring; Inline Deployment actively drops live malicious traffic; Passive Deployment monitors mirrored traffic off the main path via TAP/SPAN ports.
Each concept correctly aligns with its detection logic or placement mode. Signature-based detection checks known threat patterns, anomaly-based detection flags baseline deviations, inline placement allows live packet dropping, and out-of-band placement analyzes mirrored network traffic.

Adım Adım Çözüm

1
Differentiate between detection methods based on how threats are identified.
Signature-based detection relies on static databases of known threat signatures, whereas anomaly-based detection relies on establishing a baseline of normal behavior.
Known attack strings match signature rules, while unexpected traffic variations trigger anomaly alerts.
2
Differentiate between deployment architectures based on network traffic placement.
Inline (in-band) placement sits in line with live traffic to block malicious packets, while passive (out-of-band) placement monitors mirrored traffic streams.
Preventative action requires direct traffic path inspection (inline), while passive monitoring avoids introducing single points of network latency.

Anahtar Kavram

IDS/IPS Detection Mechanisms and Deployment Topologies
Bu soruyu puanla