When an IDS system looks for a pattern indicating a known worm, what type of detection method is it using?

Answer: A

Why would an incident handler acquire memory on a system being investigated?

Answer: C

Which could be described as a Threat Vector?

Answer: A

See the explanation below.

A threat vector is the method (crafted packet) that would be used to exercise a vulnerability (fragmentation to bypass IDS signature). An unpatched web server that is susceptible to XSS simply describes a vulnerability (unpatched) paired with a specific threat (XSS) and does not touch on the method to activate the threat. Similarly, the coding error that allows remote code execution is simply describing the pairing of a vulnerability with a threat, respectively. The botnet is an unspecified threat; there is no indication of how the threat was activated (or it's intention/capabilities; the threat).


A security device processes the first packet from destined to and recognizes a malicious anomaly. The first packet makes it to before the security devices sends a TCP RST to What type of security device is this?

Answer: B

See the explanation below.

An active response device dynamically reconfigures or alters network or system access controls, session streams, or individual packets based on triggers from packet inspection and other detection devices. Active response happens after the event has occurred, thus a single packet attack will be successful on the first attempt and blocked in future attempts. Network intrusion prevention devices are typically inline devices on the network that inspect packets and make decisions before forwarding them on to the destination. This type of device has the capability to defend against single packet attacks on the first attempt by blocking or modifying the attack inline.


Which tool uses a Snort rules file for input and by design triggers Snort alerts?

Answer: C

