nerdexam
EC-Council

312-38 · Question #97

Which of the following examines network traffic to identify threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware, and policy…

The correct answer is A. Network Behavior Analysis. Network Behavior Analysis (NBA) is correct because it works by establishing a baseline of normal network traffic patterns and then flagging anomalies - making it purpose-built to detect DDoS floods, worm propagation patterns, and policy violations that show up as unusual flow…

Network Security Monitoring and Analysis

Question

Which of the following examines network traffic to identify threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware, and policy violations?

Options

  • ANetwork Behavior Analysis
  • BNetwork-based Intrusion Prevention
  • CWireless Intrusion Prevention System
  • DHost-based Intrusion Prevention

How the community answered

(48 responses)
  • A
    88% (42)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Explanation

Network Behavior Analysis (NBA) is correct because it works by establishing a baseline of normal network traffic patterns and then flagging anomalies - making it purpose-built to detect DDoS floods, worm propagation patterns, and policy violations that show up as unusual flow behavior rather than known attack signatures.

Network-based Intrusion Prevention (B) inspects packet content against known threat signatures and can block traffic in real time, but it focuses on known attack patterns rather than behavioral anomalies in traffic flows. Wireless Intrusion Prevention Systems (C) are scoped specifically to Wi-Fi environments, monitoring for rogue access points and wireless protocol attacks - not general network flow analysis. Host-based Intrusion Prevention (D) runs on individual endpoints, monitoring processes, file access, and system calls on that specific machine rather than examining network-wide traffic patterns.

Memory tip: Think of NBA like a doctor monitoring your vital signs over time - it notices when something is abnormal compared to your baseline. The other options are more like checking a list of known symptoms (signature-based) or examining one specific organ (host-based/wireless-scoped).

Topics

#Network Behavior Analysis#Anomaly Detection#Traffic Analysis#DDoS Detection

Community Discussion

No community discussion yet for this question.

Full 312-38 Practice