ISTQB Mock App

Intrusion Detection System

An Intrusion Detection System (IDS) monitors networks or systems to detect suspicious activities, security violations, or potential attacks.

Official definition
ISTQB Official Glossary Definition
A system which monitors activities to detect violations of the security policy.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Intrusion Detection System?

IDS solutions analyze traffic, logs, and system behavior to identify possible intrusions and alert administrators to security incidents.

Detection: Monitors for known attack signatures or unusual behavior.

Alerting: Generates notifications when suspicious activity is detected.

Security support: Helps organizations respond quickly to attacks.

Real World Example

A retail company's servers are compromised for two weeks before anyone notices — the attacker steadily exfiltrates customer payment data the whole time, discovered only when a customer's bank flags suspicious card activity.

The company had firewalls and access controls designed to prevent unauthorized access, but nothing was actually watching ongoing activity for signs an intrusion had already happened and was in progress, so the attacker operated undetected for two full weeks.

A security tester evaluates whether an Intrusion detection system is properly deployed and tuned: verifying it flags unusual outbound data transfer patterns, unexpected privilege escalation, and repeated failed access attempts, and separately testing that its alerts are actually reviewed and acted on promptly.

Testing reveals the newly installed Intrusion detection system does detect the same exfiltration pattern within minutes in a simulated repeat of the attack, but its alerts were configured to email a distribution list nobody monitored — a real gap between detecting the intrusion and a human actually acting on it in time.

Practice Questions

Question 1

A company's servers are compromised for two weeks and customer payment data is exfiltrated undetected, discovered only when a customer's bank flags suspicious activity. Firewalls were in place, but what was missing?

Question 2

Which check MOST directly tests the effectiveness of an intrusion detection system?

Test your knowledge with real ISTQB-style questions

You’ve learned Intrusion Detection System. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams