ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 41 - 112-51 discussion

Report
Export

Messy, a network defender, was hired to secure an organization's internal network. He deployed an IDS in which the detection process depends on observing and comparing the observed events with the normal behavior and then detecting any deviation from it.

Identify the type of IDS employed by Messy in the above scenario.

A.
Signature-based
Answers
A.
Signature-based
B.
Stateful protocol analysis
Answers
B.
Stateful protocol analysis
C.
Anomaly-based
Answers
C.
Anomaly-based
D.
Application proxy
Answers
D.
Application proxy
Suggested answer: C

Explanation:

Anomaly-based IDS is a type of IDS that detects intrusions by comparing the observed network events with a baseline of normal behavior and identifying any deviation from it. Anomaly-based IDS can detect unknown or zero-day attacks that do not match any known signature, but they can also generate false positives due to legitimate changes in network behavior. Anomaly-based IDS can use various techniques to model the normal behavior, such as statistical analysis, machine learning, or artificial intelligence. Anomaly-based IDS is the type of IDS employed by Messy in the above scenario, as he deployed an IDS that depends on observing and comparing the observed events with the normal behavior and then detecting any deviation from it.

Reference:

Anomaly-Based Intrusion Detection System - Chapter 2: Anomaly-Based Intrusion Detection System

Network Defense Essentials (NDE) | Coursera - Week 10: Intrusion Detection and Prevention Systems

A systematic literature review for network intrusion detection system (IDS) - Section 3.2: Anomaly-based IDS

asked 18/09/2024
PANAGIOTIS SYKAS
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first