nerdexam
Cisco

352-001 · Question #505

Which action can identify and monitor denial of service attacks?

The correct answer is D. Establish normal network characteristics. Identifying and monitoring DoS attacks requires first establishing a baseline of normal network behavior so that anomalies can be detected. Without knowing what is normal, there is no reference point to classify traffic as an attack.

Designing Security

Question

Which action can identify and monitor denial of service attacks?

Options

  • ADeploy access control lists that match well-known attack vectors
  • BDeploy deep packet inspection appliances
  • CSelect attack counter-measures
  • DEstablish normal network characteristics

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    2% (1)
  • C
    7% (3)
  • D
    75% (33)

Why each option

Identifying and monitoring DoS attacks requires first establishing a baseline of normal network behavior so that anomalies can be detected. Without knowing what is normal, there is no reference point to classify traffic as an attack.

ADeploy access control lists that match well-known attack vectors

Deploying ACLs that match known attack vectors is a mitigation and blocking technique, not an identification or monitoring method.

BDeploy deep packet inspection appliances

Deep packet inspection can inspect payload content but does not by itself identify DoS attacks without a traffic baseline or signature to compare against.

CSelect attack counter-measures

Selecting counter-measures is a response action taken after an attack is already identified, not a technique for identification or monitoring.

DEstablish normal network characteristicsCorrect

Establishing normal network characteristics creates a behavioral baseline; deviations from this baseline, such as sudden traffic spikes or unusual packet rates, are the primary method for identifying and monitoring DoS attacks through anomaly detection.

Concept tested: DoS attack identification using network traffic baselining

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_zbf/configuration/xe-16/sec-data-zbf-xe-16-book/sec-zone-based-firewall.html

Topics

#DoS detection#network monitoring#baseline characteristics#anomaly detection

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice