When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?

Enhance your knowledge as a Computer Hacking Forensic Investigator with the CHFI v11 Test. Use flashcards and multiple-choice questions, complete with hints and detailed explanations, to prepare effectively and ace your exam!

Multiple Choice

When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?

Explanation:
This situation shows an inline system that not only watches traffic but actively disrupts it in real time. When the vulnerability scan is interrupted because the IDS cuts the connection, the IDS is performing active defense by blocking traffic as it passes, which is the hallmark of an Active IDS. A passive IDS would simply detect and warn without stopping traffic, so it wouldn’t interrupt the scan. While NIPS is the network version that blocks traffic, the key idea here is the active, in-path intervention, not just monitoring. Progressive IDS isn’t a standard term used for this scenario.

This situation shows an inline system that not only watches traffic but actively disrupts it in real time. When the vulnerability scan is interrupted because the IDS cuts the connection, the IDS is performing active defense by blocking traffic as it passes, which is the hallmark of an Active IDS. A passive IDS would simply detect and warn without stopping traffic, so it wouldn’t interrupt the scan. While NIPS is the network version that blocks traffic, the key idea here is the active, in-path intervention, not just monitoring. Progressive IDS isn’t a standard term used for this scenario.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy