nerdexam
Cisco

400-007 · Question #410

Most security monitoring systems use a signature-based approach to detect threats. In which two instances are systems based on Network Behavior Anomaly Detection better than signature- based systems…

The correct answer is D. intrusion threat detection E. new zero-day attacks. Intrusion threat detection: Network Behavior Anomaly Detection (NBAD) can detect unusual patterns or anomalies in network behavior, making it effective for identifying intrusions that do not match known attack signatures. New zero-day attacks: NBAD is useful in detecting…

Designing Security

Question

Most security monitoring systems use a signature-based approach to detect threats. In which two instances are systems based on Network Behavior Anomaly Detection better than signature- based systems when it comes to detecting security threat vectors? (Choose two.)

Options

  • Amalware detection
  • Bencrypted threat traffic
  • Cspyware detection
  • Dintrusion threat detection
  • Enew zero-day attacks

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    18% (5)
  • C
    7% (2)
  • D
    71% (20)

Explanation

Intrusion threat detection: Network Behavior Anomaly Detection (NBAD) can detect unusual patterns or anomalies in network behavior, making it effective for identifying intrusions that do not match known attack signatures. New zero-day attacks: NBAD is useful in detecting previously unknown (zero-day) attacks, as it focuses on unusual network behavior rather than relying on known attack signatures, which signature-based systems may miss.

Topics

#network behavior anomaly detection#zero-day attacks#threat detection#security monitoring

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice