1. What Snort Solves for Defenders
Snort is a long-standing network intrusion detection and prevention engine used for signature-based and protocol-aware traffic inspection and alerting.
Snort fits the "IDS / IPS / network detection" role in this course. Treat it as one tool in a workflow, not as a complete answer by itself. The key question is what decision quality it improves for a defender.
Before using Snort, define the operational question first (triage, validation, exposure review, monitoring, forensics, or documentation). Tool selection should follow the question, not the other way around.