Appendix . Answers to the “Do I Know This Already?” Quizzes and Q&A Questions

Chapter 1

“Do I Know This Already?” Quiz

Q&A

1.

What is a false positive?

Answer: A false positive happens when a signature triggers incorrectly during normal user traffic instead of attack traffic.

2.

What is a true positive?

Answer: A true positive happens when a signature correctly identifies an attack launched against the network.

3.

If your sensor has only two monitoring interfaces, can you operate in promiscuous and inline modes simultaneously?

Answer: No, because running inline requires a pair of sensor interfaces. If you have only two interfaces, you can run either a single interface pair (in inline mode) or two interfaces (in promiscuous ...

Get CCSP Self-Study: CCSP IPS Exam Certification Guide now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.