hardMultiple Select
200-201 Practice Question: Which TWO characteristics are typical of…
Which TWO characteristics are typical of host-based intrusion detection systems (HIDS) compared to network-based intrusion detection systems (NIDS)?
⚠ Common exam trap
Cisco often tests the misconception that HIDS are better at detecting network attacks or scaling to many devices, but the key differentiator is that HIDS provide host-level visibility (like registry and file changes) and can inspect decrypted traffic, while NIDS are network-focused and cannot see internal host events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Visibility into local system events such as file system changes and registry modifications.
Option B is correct because a HIDS agent runs directly on the endpoint and monitors local activity such as file integrity changes, registry modifications, log entries, and process behavior, giving it deep host-level visibility that a NIDS, which only sees network packets, cannot provide. Option C is correct because a HIDS can inspect data after it has been decrypted on the host, so it can analyze encrypted traffic (e.g., TLS/HTTPS sessions) at the endpoint, whereas a NIDS typically sees only ciphertext on the wire and cannot decrypt it. Option A is wrong because protecting many devices simultaneously is a strength of NIDS, which can monitor a whole network segment from a central sensor, while HIDS requires an agent per host. Option D is wrong because HIDS agents run on the host and are themselves exposed to host-based attacks (e.g., tampering, rootkits), making them more—not less—susceptible. Option E is wrong because lower latency in detecting network attacks is characteristic of NIDS, which inspects traffic in real time on the network path, not of HIDS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Better suited for protecting a large number of devices simultaneously.
Why it's wrong here
HIDS agents must be installed and maintained per host, so scaling to many devices multiplies deployment and management overhead. NIDS sensors sit at network chokepoints and cover all downstream hosts from one point, making NIDS the choice for broad simultaneous coverage.
- ✓
Visibility into local system events such as file system changes and registry modifications.
Why this is correct
Because a HIDS agent runs on the host itself, it observes local file system changes, registry modifications and process activity that network sensors cannot see. This host-level telemetry satisfies the stem's comparison against NIDS, which only inspects traffic crossing the wire.
- ✓
Ability to inspect encrypted traffic at the host level.
Why this is correct
A HIDS agent sits on the endpoint, so it reads data after TLS termination, exposing plaintext that a NIDS would only see as ciphertext. This satisfies the stem's comparison, since network sensors cannot decrypt traffic without keys or interception.
- ✗
Less susceptible to host-based attacks.
Why it's wrong here
HIDS runs on the host it monitors, so it cannot be less susceptible to attacks against that same host; compromise of the host typically compromises the agent. It is tempting because HIDS analyses host internals such as file integrity and system calls, which NIDS cannot see, making it the right pick when detecting local privilege escalation or tampering.
- ✗
Lower latency in detecting network attacks.
Why it's wrong here
HIDS monitors host logs, file integrity and system calls, so it cannot observe network traffic and therefore adds no network-attack detection latency advantage. NIDS inspects packets at network segments, giving it that visibility; HIDS is chosen for endpoint-level compromise detection instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.