Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GAQM Exam CFA-001 Topic 1 Question 80 Discussion

Actual exam question for GAQM's CFA-001 exam
Question #: 80
Topic #: 1
[All CFA-001 Questions]

An intrusion detection system (IDS) gathers and analyzes information from within a computer or a network to identify any possible violations of security policy, including unauthorized access, as well as misuse.

Which of the following intrusion detection systems audit events that occur on a specific host?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Gussie
10 days ago
True, true. I'm feeling pretty confident about B) Host-based intrusion detection now. Let's just hope the exam question doesn't try to trick us with some obscure IDS technology we've never heard of!
upvoted 0 times
...
Arthur
12 days ago
Good point. Log file monitoring and file integrity checking are more like supporting tools or techniques that can be used in conjunction with an IDS, but they're not full-fledged IDS solutions on their own.
upvoted 0 times
...
Haydee
13 days ago
I agree, but what about the other options? I'm a bit iffy on C) Log file monitoring and D) File integrity checking. Are those considered types of intrusion detection systems too?
upvoted 0 times
...
Ivan
14 days ago
Exactly! The question specifically says the IDS gathers and analyzes information from within a computer or network, so host-based is the way to go.
upvoted 0 times
...
William
16 days ago
Yeah, that's what I was thinking too. A host-based IDS monitors and analyzes events on a specific host or system, whereas a network-based IDS looks at traffic across the network.
upvoted 0 times
...
Taryn
18 days ago
This question seems pretty straightforward. I'm pretty sure the answer is B) Host-based intrusion detection.
upvoted 0 times
...

Save Cancel