ExamGecko
Question list
Search
Search

Question 276 - CISM discussion

Report
Export

An anomaly-based intrusion detection system (IDS) operates by gathering data on:

A.
normal network behavior and using it as a baseline lor measuring abnormal activity
Answers
A.
normal network behavior and using it as a baseline lor measuring abnormal activity
B.
abnormal network behavior and issuing instructions to the firewall to drop rogue connections
Answers
B.
abnormal network behavior and issuing instructions to the firewall to drop rogue connections
C.
abnormal network behavior and using it as a baseline for measuring normal activity
Answers
C.
abnormal network behavior and using it as a baseline for measuring normal activity
D.
attack pattern signatures from historical data
Answers
D.
attack pattern signatures from historical data
Suggested answer: A

Explanation:

An anomaly-based intrusion detection system (IDS) operates by gathering data on normal network behavior and using it as a baseline for measuring abnormal activity. This is important because it allows the IDS to detect any activity that is outside of the normal range of usage for the network, which can help to identify potential malicious activity or security threats. Additionally, the IDS will monitor for any changes in the baseline behavior and alert the administrator if any irregularities are detected. By contrast, signature-based IDSs operate by gathering attack pattern signatures from historical data and comparing them against incoming traffic in order to identify malicious activity.

asked 01/10/2024
Piyush Zope
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first