6.0 IPS

6.0 IPS

6.1 Describe IPS deployment considerations

  • 6.1.a Network-based IPS vs. host-based IPS
  • 6.1.b Modes of deployment (inline, promiscuous – SPAN, tap)
  • 6.1.c Placement (positioning of the IPS within the network)
  • 6.1.d False positives, false negatives, true positives, true negatives

6.2 Describe IPS technologies

  • 6.2.a Rules/signatures
  • 6.2.b Detection/signature engines
  • 6.2.c Trigger actions/responses (drop, reset, block, alert, monitor/log, shun)
  • 6.2.d Blacklist (static and dynamic)
Advertisements