QuestionQ135

Secure Software Concepts

Which of the following intrusion detection systems (IDS) monitors network traffic and compares it with an established baseline?

  • A File-based
  • B Network-based
  • C Anomaly-based
  • D Signature-based
Explanation

An anomaly-based IDS learns or uses a baseline of normal network behavior and generates alerts when traffic significantly deviates from that baseline. A network-based IDS describes where monitoring occurs, whereas signature-based detection compares activity with known attack signatures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!