nerdexam
EC-Council

212-82 · Question #132

NetSafe Corp, recently conducted an overhaul of its entire network. This refresh means that the old baseline traffic signatures no longer apply. The security team needs to establish a new baseline…

The correct answer is B. Utilize machine learning algorithms to analyze traffic for a month and generate a dynamic baseline. Explanation Option B is correct because machine learning algorithms can dynamically analyze traffic patterns over an extended period, adapting to evolving network behavior and distinguishing between normal and suspicious activity with far greater accuracy than static methods…

Submitted by haru.x· Mar 6, 2026Cloud Security Operations & Incident Response

Question

NetSafe Corp, recently conducted an overhaul of its entire network. This refresh means that the old baseline traffic signatures no longer apply. The security team needs to establish a new baseline that comprehensively captures both normal and suspicious activities. The goal is to ensure real-time detection and mitigation of threats without generating excessive false positives. Which approach should NetSafe Corp, adopt to effectively set up this baseline?

Options

  • AContinuously collect data for a week and define the average traffic pattern as the baseline.
  • BUtilize machine learning algorithms to analyze traffic for a month and generate a dynamic baseline.
  • CAnalyze the last year's traffic logs and predict the baseline using historical data.
  • DConduct a red team exercise and base the new baseline on the identified threats.

How the community answered

(68 responses)
  • A
    22% (15)
  • B
    62% (42)
  • C
    6% (4)
  • D
    10% (7)

Explanation

Explanation

Option B is correct because machine learning algorithms can dynamically analyze traffic patterns over an extended period, adapting to evolving network behavior and distinguishing between normal and suspicious activity with far greater accuracy than static methods - directly minimizing false positives while enabling real-time threat detection. Option A is flawed because one week of data is insufficient to capture the full range of legitimate traffic patterns (e.g., monthly cycles, business rhythms), and averaging alone cannot identify nuanced threat signatures. Option C fails because the network overhaul means historical logs are no longer relevant - the old infrastructure's traffic patterns don't reflect the new environment, making predictions unreliable. Option D is incorrect because red team exercises focus on known attack vectors and cannot establish a comprehensive baseline of normal traffic; they supplement security but don't define operational norms.

Memory Tip: Think "Dynamic = Defensive" - when a network changes, you need a flexible, learning-based approach (ML) rather than a rigid, historical, or short-term snapshot. The longer the observation window + adaptive intelligence = the most accurate baseline.

Topics

#Network Baselines#Anomaly Detection#Machine Learning#Network Security Operations

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice