ExamGecko
Question list
Search
Search

Related questions











Question 247 - CISA discussion

Report
Export

Which of the following is the BEST indicator of the effectiveness of signature-based intrusion detection systems (lDS)?

A.
An increase in the number of identified false positives
Answers
A.
An increase in the number of identified false positives
B.
An increase in the number of detected Incidents not previously identified
Answers
B.
An increase in the number of detected Incidents not previously identified
C.
An increase in the number of unfamiliar sources of intruders
Answers
C.
An increase in the number of unfamiliar sources of intruders
D.
An increase in the number of internally reported critical incidents
Answers
D.
An increase in the number of internally reported critical incidents
Suggested answer: B

Explanation:

Signature-based intrusion detection systems (IDS) are systems that compare network traffic with predefined patterns of known attacks, called signatures. The effectiveness of signature-based IDS depends on how well they can detect new or unknown attacks that are not in their signature database. Therefore, an increase in the number of detected incidents not previously identified is the best indicator of the effectiveness of signature-based IDS, as it shows that they can recognize novel or modified attacks.

asked 18/09/2024
shafinaaz hossenny
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first