QuestionQ96

Security Design

Most security-monitoring systems use a signature-based method to identify threats. In which two cases are Network Behavior Anomaly Detection–based systems better than signature-based systems at detecting security threat vectors?

Choose two
  • A malware detection
  • B encrypted threat traffic
  • C spyware detection
  • D intrusion threat detection
  • E new zero-day attacks
Explanation

Network Behavior Anomaly Detection identifies departures from established normal network behavior rather than matching known signatures. This makes it effective for previously unseen zero-day attacks and for suspicious encrypted traffic, where payload inspection and signature matching may be unavailable or ineffective.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!