Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Security Operations & Monitoring

IDS

Intrusion Detection System

Monitors traffic or hosts and alerts on suspected malicious activity.

An IDS inspects network or host activity and raises alerts when it observes suspicious or known malicious patterns, but it does not block traffic on its own. Detection uses signature based matching for known threats or anomaly based modeling to flag deviations from a baseline. Because it only reports, it is often deployed passively on a mirrored port. The key exam contrast is the IPS, which sits inline and can actively drop offending traffic, trading the risk of false positives blocking legitimate activity.

Memory hook

Detects and alerts. It sits passively off to the side: it watches, it does not block.

Related terms

Looking IDS up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.