An anomaly-based intrusion detection system (IDS) operates by gathering data on:
A.
normal network behavior and using it as a baseline lor measuring abnormal activity
B.
abnormal network behavior and issuing instructions to the firewall to drop rogue connections
C.
abnormal network behavior and using it as a baseline for measuring normal activity
D.
attack pattern signatures from historical data
The Answer Is:
A
This question includes an explanation.
Explanation:
An anomaly-based intrusion detection system (IDS) operates by gathering data on normal network behavior and using it as a baseline for measuring abnormal activity. This is important because it allows the IDS to detect any activity that is outside of the normal range of usage for the network, which can help to identify potential malicious activity or security threats. Additionally, the IDS will monitor for any changes in the baseline behavior and alert the administrator if any irregularities are detected. By contrast, signature-based IDSs operate by gathering attack pattern signatures from historical data and comparing them against incoming traffic in order to identify malicious activity.
CISM PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"