What term describes a set of rules used by an IDS or IPS to detect typical intrusion activity?

IT Exam Items RepositoryCategory: CCNA SecurityWhat term describes a set of rules used by an IDS or IPS to detect typical intrusion activity?

What term describes a set of rules used by an IDS or IPS to detect typical intrusion activity?

  • definition
  • trigger
  • signature
  • event file

Explanation: A signature is a set of rules that an IDS and an IPS use to detect typical intrusion activity, such as DoS attacks. These signatures uniquely identify specific worms, viruses, protocol anomalies, and malicious traffic​.

Related exam: CCNA Security Practice Final Exam Answers
Related exam: Module 12: Quiz – IPS Operation and Implementation Network Security