IDS
Intrusion Detection System
Monitors traffic or hosts and alerts on suspected malicious activity.
An IDS inspects network or host activity and raises alerts when it observes suspicious or known malicious patterns, but it does not block traffic on its own. Detection uses signature based matching for known threats or anomaly based modeling to flag deviations from a baseline. Because it only reports, it is often deployed passively on a mirrored port. The key exam contrast is the IPS, which sits inline and can actively drop offending traffic, trading the risk of false positives blocking legitimate activity.
Detects and alerts. It sits passively off to the side: it watches, it does not block.
Looking IDS up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
