N10-005 · Question #548
Which of the following could be used to stop unknown threats?
The correct answer is C. Behavior based IPS. A behavior-based (anomaly-based) IPS detects threats by monitoring network or system activity and flagging deviations from a known baseline of normal behavior. Because it identifies suspicious patterns rather than matching known attack signatures, it can detect zero-day…
Question
Which of the following could be used to stop unknown threats?
Options
- ADMZ
- BSignature based IPS
- CBehavior based IPS
- DHoneypots
How the community answered
(36 responses)- A8% (3)
- B3% (1)
- C86% (31)
- D3% (1)
Explanation
A behavior-based (anomaly-based) IPS detects threats by monitoring network or system activity and flagging deviations from a known baseline of normal behavior. Because it identifies suspicious patterns rather than matching known attack signatures, it can detect zero-day exploits and previously unknown threats. A signature-based IPS only recognizes threats with existing signatures. A DMZ is a network segmentation strategy, and honeypots are decoy systems used to observe attackers - neither actively stops unknown threats in real time.
Topics
Community Discussion
No community discussion yet for this question.