Which intrusion detection system audits events on a specific host?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

Which intrusion detection system audits events on a specific host?

Explanation:
Auditing events on a specific host is the job of a host-based intrusion detection system. It sits on the machine itself and monitors local activity—security logs, file access, system calls, and process behavior—giving visibility into what happens inside that particular host. In contrast, a network-based intrusion detection system watches network traffic across a segment, not the internal events of one machine, and log file monitoring or file integrity checking are techniques often used within host-based systems rather than a separate category of IDS.

Auditing events on a specific host is the job of a host-based intrusion detection system. It sits on the machine itself and monitors local activity—security logs, file access, system calls, and process behavior—giving visibility into what happens inside that particular host. In contrast, a network-based intrusion detection system watches network traffic across a segment, not the internal events of one machine, and log file monitoring or file integrity checking are techniques often used within host-based systems rather than a separate category of IDS.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy