An Intrusion Detection System monitors network or host activity and generates alerts when suspicious behavior is detected. Because it identifies potential incidents rather than blocking or remediating them, it is categorized as a detective control. Preventive controls (e.g., firewalls) attempt to stop incidents, corrective controls focus on recovery, and deterrent controls primarily discourage attackers.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between Detective Controls and Preventive Controls?
Open an interactive chat with Bash
Can you explain how an Intrusion Detection System (IDS) works?