IDS/IPS
You will learn how Snort and Suricata detect attacks via signatures and anomalies, when to deploy inline as an IPS versus passively off a SPAN port, and how attackers evade detection with fragmentation and encoding. Interviewers probe the detection-vs-prevention trade-off and false-positive tuning because both dominate real deployments.
on this pageshowhide
explore
- The Sensor's Position16 questions
- Silent Discards4 questions
- Ciphertext at the Tap4 questions
- Watching the Interior4 questions
- Inspection You Cannot Afford4 questions
- Expressing a Detection12 questions
- Anatomy of a Signature4 questions
- Parsing Instead of Matching4 questions
- Making Traffic Not Match4 questions
- Standing in the Path12 questions
- Alerting Versus Preventing4 questions
- The Window You Scheduled4 questions
- Suppression and Its Debt4 questions
questions
page 2 of 2An optical tap yields two simplex feeds — what must you spend so one IDS engine sees both halves of an intruder's session?
basics
~20 sYou must re-aggregate the two directions and keep them together all the way to one engine instance: enough aggregation capacity for both directions at peak, and flow-aware or symmetric load balancing so a session's two halves land on the same receive queue and worker.
Your IDS reassembly-policy map is keyed to address ranges a merger renumbered - where does an attacker get through, and what does re-deriving cost?
basics
~20 sWherever the map now names the wrong stack, the sensor resolves overlapping data the way the old occupant did, so an attacker who fingerprints the real host wins there. Re-deriving means rebuilding an OS inventory for an estate you inherited and do not control.
A Zeek-style sensor restarts mid-transfer: what can it no longer say about files an intruder moved inside that partner session?
basics
~20 sEssentially nothing above the transport. Analyzers attach from a stream's opening bytes, so a session already in progress yields no protocol identification, no file records and no hashes - only a partial connection record until it ends.
A branch IPS has raised no alerts in a week and there are no local hands -- how do you prove it is not passing an intruder unjudged?
basics
~20 sSilence proves nothing, so make the box prove itself: poll its bypass and engine state, compare the bytes it claims to have inspected against the router's flow records for that link, and schedule a benign test a known rule must catch.
You set one IDS scan-signature threshold estate-wide — why does that hide an intruder on your noisiest segment?
basics
~10 sA threshold is a number relative to a baseline, and campus segments differ by orders of magnitude. One value high enough to survive the noisiest segment sets a bar an intruder simply stays under.
A Suricata content rule matches one encoding of an attacker technique and the coverage matrix says 'detected'. What do you publish with the rule, and what do you refuse to claim?
basics
~20 sPublish the evasion margin: the variants tested and matched, the variants known not to match, and the conditions - buffer, direction, ports - under which the rule holds. Refuse the binary 'detected', because someone will stop funding the gap on the strength of it.
A plant manager must sign that an IPS rule may stop the line to block an intruder - what belongs in that proposal?
basics
~20 sEverything needed to compare two outages in one set of units: the exposure if the intruder is not blocked, the worst credible wrong drop and its cost per minute, the exact rules enforced, and who can revoke it how fast.
Your MSP contract promises full traffic inspection at a fixed latency — how do you state the real ceiling before an intruder finds it?
basics
~20 sFull inspection and a latency figure at the contracted throughput cannot both hold at peak. Write the configured limits into the service description in plain words, price the alternative, and have the tenant's risk owner accept or fund the gap in writing.
Budget funds interior sensors on one segment in five: how do you choose, and what do you tell an auditor about the segments an intruder could cross unseen?
basics
~20 sChoose by what a compromise there would cost and by whether any other record would exist, not by traffic volume. Then publish a dated per-segment list stating what is sensed, at what depth, and where no record would exist at all — and have the risk owner accept it, not the security team.
When do you give up the passive mirror position and terminate egress TLS instead, and who signs for it?
basics
~20 sOnly when you must know what was inside the traffic and the endpoint cannot tell you. Terminating spends a copy that can never break production, and buys plaintext custody, an in-path failure domain, and clients that fail rather than be read.
showing 31–40 of 40