QuestionQ68

Network Monitoring and Analysis

Rhett, a security professional at an organization, was directed to deploy an IDS solution on the corporate network to protect against evolving threats. For this purpose, Rhett chose an IDS solution that initially builds models of possible intrusions and then compares those models with incoming events to make detection decisions.

Identify the detection method used by the IDS solution in this scenario.

  • A Not-use detection
  • B Protocol anomaly detection
  • C Anomaly detection
  • D Signature recognition
Explanation

Signature recognition detects intrusions by matching incoming events or activity against models of known malicious patterns, commonly called signatures. It differs from anomaly detection, which identifies deviations from an established baseline of normal behavior.

Community Discussion

No comments yet. Be the first to start the discussion!