nerdexam
CompTIA

N10-005 · Question #548

Which of the following could be used to stop unknown threats?

The correct answer is C. Behavior based IPS. A behavior-based (anomaly-based) IPS detects threats by monitoring network or system activity and flagging deviations from a known baseline of normal behavior. Because it identifies suspicious patterns rather than matching known attack signatures, it can detect zero-day…

Network security

Question

Which of the following could be used to stop unknown threats?

Options

  • ADMZ
  • BSignature based IPS
  • CBehavior based IPS
  • DHoneypots

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    86% (31)
  • D
    3% (1)

Explanation

A behavior-based (anomaly-based) IPS detects threats by monitoring network or system activity and flagging deviations from a known baseline of normal behavior. Because it identifies suspicious patterns rather than matching known attack signatures, it can detect zero-day exploits and previously unknown threats. A signature-based IPS only recognizes threats with existing signatures. A DMZ is a network segmentation strategy, and honeypots are decoy systems used to observe attackers - neither actively stops unknown threats in real time.

Topics

#IPS#behavior-based detection#intrusion prevention#unknown threats

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice