nerdexam
(ISC)2

SSCP · Question #949

Attributes that characterize an attack are stored for reference using which of the following Intrusion Detection System (IDS) ?

The correct answer is A. signature-based IDS. A signature-based Intrusion Detection System (IDS) identifies attacks by comparing observed activities against a database of known attack patterns.

Submitted by devops_kid· Apr 18, 2026Network and Communications Security

Question

Attributes that characterize an attack are stored for reference using which of the following Intrusion Detection System (IDS) ?

Options

  • Asignature-based IDS
  • Bstatistical anomaly-based IDS
  • Cevent-based IDS
  • Dinferent-based IDS

How the community answered

(52 responses)
  • A
    88% (46)
  • B
    4% (2)
  • C
    2% (1)
  • D
    6% (3)

Why each option

A signature-based Intrusion Detection System (IDS) identifies attacks by comparing observed activities against a database of known attack patterns.

Asignature-based IDSCorrect

Signature-based IDSs maintain a database of specific attack patterns, or 'signatures,' which are characteristic attributes or sequences of events associated with known threats. When network traffic or system logs match one of these predefined signatures, the IDS triggers an alert, indicating a potential intrusion.

Bstatistical anomaly-based IDS

Statistical anomaly-based IDSs detect deviations from established baselines of normal network or system behavior, rather than matching against known attack attributes.

Cevent-based IDS

Event-based IDS is not a standard classification; all IDSs process events, but this doesn't define the detection methodology.

Dinferent-based IDS

Inferent-based IDS is not a recognized or standard category for Intrusion Detection Systems.

Concept tested: Signature-based IDS functionality

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-baselines/security-baselines-faq#intrusion-detection-system-ids

Topics

#Intrusion Detection Systems#Signature-based detection#Network security tools

Community Discussion

No community discussion yet for this question.

Full SSCP Practice