exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 100 discussion

Actual exam question from Cisco's 200-201
Question #: 100
Topic #: 1
[All 200-201 Questions]

Which system monitors local system operation and local network access for violations of a security policy?

  • A. host-based intrusion detection
  • B. systems-based sandboxing
  • C. host-based firewall
  • D. antivirus
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Torvalds
Highly Voted 3 years, 3 months ago
i think that "A.host-based intrusion detection". HIDS is capable of monitoring the internals of a computing system as well as the network packets on its network interfaces. Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.
upvoted 22 times
...
anonymous1966
Highly Voted 2 years, 10 months ago
"A" is correct. The question is copy and past of Wikipedia definition: An intrusion detection system (IDS)[1] is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically reported either to an administrator or collected centrally using a security information and event management (SIEM) system. A SIEM system combines outputs from multiple sources and uses alarm filtering techniques to distinguish malicious activity from false alarms. https://en.wikipedia.org/wiki/Intrusion_detection_system
upvoted 9 times
...
Faio
Most Recent 1 year ago
The answer is A. Host-based intrusion detection (HIDS) is a security system that monitors a computer system for malicious activity or policy violations. HIDSs can be used to detect a variety of threats, including unauthorized access, malware, and data exfiltration. Systems-based sandboxing is a security technique that isolates applications in a controlled environment to prevent them from causing harm to the host system. Host-based firewall is a security system that controls incoming and outgoing network traffic on a host system. Antivirus is a software application that detects and removes malware from a computer system.
upvoted 1 times
...
SecurityGuy
1 year, 4 months ago
Selected Answer: A
Keyword: "Monitors" - It is an IDS function. - An Intrusion Detection System (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. - A host based firewall does not monitor local system operations. A firewall is no more than an ACL matching traffic in and out of a system based on how it's configured.
upvoted 1 times
...
Eng_ahmedyoussef
1 year, 10 months ago
Selected Answer: A
A. is the best answer HIDS is capable of monitoring the internals of a computing system as well as the network packets on its network interfaces. Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.
upvoted 2 times
...
kyle942
1 year, 10 months ago
Selected Answer: A
A host intrusion detection system uses rules and policies in order to search your log files, flagging those with events or activity the rules have determined could be indicative of potentially malicious behavior.
upvoted 1 times
...
Tobds234
2 years, 3 months ago
Selected Answer: A
Host-based firewall is a piece of software running on a single Host that can restrict incoming and outgoing Network activity for that host only.
upvoted 1 times
...
PanteLa_26
2 years, 5 months ago
Selected Answer: A
Should be A imho, key word "monitors"
upvoted 1 times
...
hukkaru
2 years, 6 months ago
Selected Answer: A
HIDS monitors local system, firewall not. Answer is A
upvoted 1 times
...
HarryPotter69
2 years, 10 months ago
Answer is A An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations.
upvoted 6 times
...
Alannn
2 years, 10 months ago
A host based firewall does not monitor local system operations. A firewall is no more than an ACL matching traffic in and out of a system based on how it's configured. A significant advantage of HIPS is that it can monitor operating system processes. "A HIPS often monitors memory, kernel, and network state, log files, ... protects system integrity by detecting changes to critical operating system files."
upvoted 4 times
Alannn
2 years, 10 months ago
In this case its HIDS and not HIPS, which one could argue would only make choice A even stronger seeing that a HIDS only monitors (both network and system files) whilst a firewall monitors network only but also intervene and blocks, which is more then just monitoring.
upvoted 1 times
...
...
afifulinuha
2 years, 11 months ago
IDS Global detection, Firewall Local.. and i agree with the answer.. no doubt bro make it simple
upvoted 1 times
...
mrodriguezb
3 years ago
It says security policies. In the firewall the concept of security policies is handled. I agree with the answer
upvoted 2 times
...
JohnBB
3 years, 2 months ago
The key word is "monitors". And it's IDS work.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...