ExamGecko
Question list
Search
Search

Related questions











Question 557 - CISA discussion

Report
Export

When reviewing the functionality of an intrusion detection system (IDS), the IS auditor should be MOST concerned if:

A.
legitimate packets blocked by the system have increased
Answers
A.
legitimate packets blocked by the system have increased
B.
actual attacks have not been identified
Answers
B.
actual attacks have not been identified
C.
detected events have increased
Answers
C.
detected events have increased
D.
false positives have been reported
Answers
D.
false positives have been reported
Suggested answer: B

Explanation:

The main purpose of an IDS is to detect and report malicious or suspicious activity on a network or a host. If an IDS fails to identify actual attacks, it means that the IDS is not functioning properly or effectively, and it exposes the organization to serious security risks and potential damage. This is the most concerning scenario for an IS auditor, as it indicates a major deficiency in the IDS performance and configuration.

Reference What is an intrusion detection system (IDS)? What is Intrusion Detection Systems (IDS)? How does it Work? When reviewing an intrusion detection system (IDS), an IS auditor ... Intrusion Detection Systems (IDS)---An Overview with a Generalized ... An overview of issues in testing intrusion detection systems - NIST A Review of Intrusion Detection Systems and Their ...

asked 18/09/2024
Jason Wang
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first