nerdexam
(ISC)2

CISSP-ISSAP · Question #196

Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?

The correct answer is B. Anomaly-based. Anomaly-based IDS works by learning what "normal" looks like on a network (the baseline), then alerting when traffic deviates from that profile - making it the only option here that fits the "compares against a baseline" definition. A (Network-based) describes where the IDS is…

Infrastructure Security

Question

Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?

Options

  • ANetwork-based
  • BAnomaly-based
  • CFile-based
  • DSignature-based

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    93% (28)
  • C
    3% (1)

Explanation

Anomaly-based IDS works by learning what "normal" looks like on a network (the baseline), then alerting when traffic deviates from that profile - making it the only option here that fits the "compares against a baseline" definition.

  • A (Network-based) describes where the IDS is deployed (on the network), not how it detects threats. A network-based IDS can use either anomaly or signature methods.
  • C (File-based) is a distractor; this isn't a standard IDS category - it conflates IDS with file integrity monitoring (e.g., Tripwire).
  • D (Signature-based) compares traffic against a database of known attack patterns, not a baseline - it can't detect novel threats with no prior signature.

Memory tip: Think anomaly = abnormal vs. normal. If it's looking for something unusual compared to a learned standard, it's anomaly-based. If it's matching against a known "wanted poster" of attacks, it's signature-based.

Topics

#Anomaly-based IDS#IDS detection methods#Baseline comparison#Network intrusion detection

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice