I'd go with B, since WPA2-PSK with AES is the standard secure upgrade over WEP. The official study guide for CEH definitely emphasizes moving away from WEP to WPA2 or better. Anyone see any recent practice questions pushing for anything else?
I get that some folks might confuse this with a firewall rule, but the alert tcp ... msg part is pure IDS stuff. Firewalls don't use 'alert' or msg options like that. Seems obvious for D, unless I'm missing a weird trick in iptables config?
D imo here. If the IDS flagged legit admin work as an attack, that’s classic false positive territory. Only flips if the admin wasn’t authorized or their access was suspicious, but the question makes it sound routine. Seen this come up on other practice sets too.
I thought B (WISS) since it sounds close to wireless, but now I’m unsure. Is the question specifically asking for active prevention or just detection? That would make a difference here.