HIDS
Host-based Intrusion Detection System
Software on a host that detects suspicious activity and alerts.
A host based intrusion detection system runs on an individual endpoint and watches local artifacts such as logs, file integrity, processes, and registry changes to flag suspicious behavior. Because it sits on the host, it can inspect activity that never crosses the network, including encrypted sessions after decryption. It matters for detecting insider misuse and post compromise actions. The exam distinction is that a HIDS only alerts, while a HIPS can actively block, and a network IDS sees traffic rather than host internals.
Host-based: runs on one machine and watches that single host.
Looking HIDS up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
