QuestionQ286

Network Security and Architecture

You are the Network Administrator for a large corporate network. You need to monitor all traffic on the local network for suspicious activity and receive a notification when a possible attack is underway. Which of the following actions should you take?

  • A Install a DMZ firewall
  • B Enable verbose logging on the firewall
  • C Install a host-based IDS
  • D Install a network-based IDS
Explanation

A network-based IDS monitors and analyzes traffic on network segments to identify suspicious activity and generate alerts. This provides visibility across the local network, whereas a host-based IDS monitors only a single host.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!