ECCouncil Exam Questions

which of the following?

When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?

A.
Drops the packet and moves on to the next one

B.
Continues to evaluate the packet until all rules are checked

C.
Stops checking rules, sends an alert, and lets the packet continue

D.
Blocks the connection with the source IP address in the packet