nerdexam
EC-Council

312-50V13 · Question #337

Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?

The correct answer is B. Can identify unknown attacks. Anomaly-based Intrusion Detection Systems (IDS) are conceptually distinct from signature-based IDSs due to their method of identifying threats.

Submitted by akirajp· Mar 6, 2026Evading IDS, Firewalls, and Honeypots

Question

Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?

Options

  • AProduces less false positives
  • BCan identify unknown attacks
  • CRequires vendor updates for a new threat
  • DCannot deal with encrypted network traffic

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    92% (24)
  • C
    4% (1)

Why each option

Anomaly-based Intrusion Detection Systems (IDS) are conceptually distinct from signature-based IDSs due to their method of identifying threats.

AProduces less false positives

Anomaly-based IDSs are typically prone to producing more false positives than signature-based IDSs because any unusual, yet legitimate, activity can trigger an alert.

BCan identify unknown attacksCorrect

Anomaly-based IDSs establish a baseline of normal system or network behavior and flag any significant deviations from this baseline as potential intrusions, enabling them to identify novel or previously unknown attacks (zero-day threats) without requiring specific signatures.

CRequires vendor updates for a new threat

Anomaly-based IDSs do not rely on vendor updates for new threats in the same manner as signature-based systems; their strength lies in detecting deviations from a learned normal behavior.

DCannot deal with encrypted network traffic

Both anomaly-based and signature-based IDSs face challenges in inspecting encrypted network traffic if decryption keys are not available, so this is not a distinguishing characteristic of anomaly-based IDS over signature-based.

Concept tested: Intrusion Detection System (IDS) types and characteristics

Topics

#IDS#Anomaly-based IDS#Signature-based IDS#Unknown attacks

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice