When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

When a vulnerability scan is interrupted because the IDS cuts off your connection, what type of IDS is being used?

Explanation:
This situation shows an inline system that not only watches traffic but actively disrupts it in real time. When the vulnerability scan is interrupted because the IDS cuts the connection, the IDS is performing active defense by blocking traffic as it passes, which is the hallmark of an Active IDS. A passive IDS would simply detect and warn without stopping traffic, so it wouldn’t interrupt the scan. While NIPS is the network version that blocks traffic, the key idea here is the active, in-path intervention, not just monitoring. Progressive IDS isn’t a standard term used for this scenario.

This situation shows an inline system that not only watches traffic but actively disrupts it in real time. When the vulnerability scan is interrupted because the IDS cuts the connection, the IDS is performing active defense by blocking traffic as it passes, which is the hallmark of an Active IDS. A passive IDS would simply detect and warn without stopping traffic, so it wouldn’t interrupt the scan. While NIPS is the network version that blocks traffic, the key idea here is the active, in-path intervention, not just monitoring. Progressive IDS isn’t a standard term used for this scenario.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy