Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50 All Questions

View all questions & answers for the 312-50 exam

Exam 312-50 topic 4 question 1 discussion

Actual exam question from ECCouncil's 312-50
Question #: 1
Topic #: 4
[All 312-50 Questions]

When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?

  • A. Drops the packet and moves on to the next one
  • B. Continues to evaluate the packet until all rules are checked
  • C. Stops checking rules, sends an alert, and lets the packet continue
  • D. Blocks the connection with the source IP address in the packet
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
bic3p
3 months ago
Selected Answer: C
The correct answer is C. Stops checking rules, sends an alert, and lets the packet continue. When an alert rule is matched in a network-based IDS like Snort, the IDS will: Stop checking rules: Once a rule is matched, Snort will stop evaluating the packet against the remaining rules. Send an alert: The IDS will generate an alert to notify the system administrator or security team about the potential threat. Let the packet continue: The packet will be allowed to continue through the network, as the IDS is only monitoring and alerting, not blocking traffic.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...