CISSP-ISSAP · Question #196
Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?
The correct answer is B. Anomaly-based. Anomaly-based IDS works by learning what "normal" looks like on a network (the baseline), then alerting when traffic deviates from that profile - making it the only option here that fits the "compares against a baseline" definition. A (Network-based) describes where the IDS is…
Question
Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?
Options
- ANetwork-based
- BAnomaly-based
- CFile-based
- DSignature-based
How the community answered
(30 responses)- A3% (1)
- B93% (28)
- C3% (1)
Explanation
Anomaly-based IDS works by learning what "normal" looks like on a network (the baseline), then alerting when traffic deviates from that profile - making it the only option here that fits the "compares against a baseline" definition.
- A (Network-based) describes where the IDS is deployed (on the network), not how it detects threats. A network-based IDS can use either anomaly or signature methods.
- C (File-based) is a distractor; this isn't a standard IDS category - it conflates IDS with file integrity monitoring (e.g., Tripwire).
- D (Signature-based) compares traffic against a database of known attack patterns, not a baseline - it can't detect novel threats with no prior signature.
Memory tip: Think anomaly = abnormal vs. normal. If it's looking for something unusual compared to a learned standard, it's anomaly-based. If it's matching against a known "wanted poster" of attacks, it's signature-based.
Topics
Community Discussion
No community discussion yet for this question.