nerdexam
CompTIA

SY0-301 · Question #529

The network security engineer just deployed an IDS on the network, but the Chief Technical Officer (CTO) has concerns that the device is only able to detect known anomalies. Which of the following…

The correct answer is A. Signature Based IDS. A signature-based IDS operates by matching observed traffic or behavior against a database of pre-defined attack signatures (patterns of known threats). It is highly effective against known attacks but completely blind to zero-day or novel attacks because no signature exists…

Security operations

Question

The network security engineer just deployed an IDS on the network, but the Chief Technical Officer (CTO) has concerns that the device is only able to detect known anomalies. Which of the following types of IDS has been deployed?

Options

  • ASignature Based IDS
  • BHeuristic IDS
  • CBehavior Based IDS
  • DAnomaly Based IDS

How the community answered

(34 responses)
  • A
    94% (32)
  • B
    3% (1)
  • D
    3% (1)

Explanation

A signature-based IDS operates by matching observed traffic or behavior against a database of pre-defined attack signatures (patterns of known threats). It is highly effective against known attacks but completely blind to zero-day or novel attacks because no signature exists for them yet - which is exactly the CTO's concern. Heuristic IDS (B), behavior-based IDS (C), and anomaly-based IDS (D) all establish a baseline of normal activity and can flag deviations, enabling detection of unknown or novel attacks. The limitation described - only detecting known threats - is the defining characteristic of a signature-based system.

Topics

#signature-based IDS#intrusion detection#known threats#IDS types

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice