nerdexam
CompTIA

SY0-301 · Question #547

Joe, the Chief Technical Officer (CTO), is concerned about new malware being introduced into the corporate network. He has tasked the security engineers to implement a technology that is capable of…

The correct answer is B. Anomaly Based IDS. An Anomaly-Based IDS establishes a baseline of normal network behavior and alerts when traffic deviates from that baseline, making it ideal for detecting new or unusual malware activity.

Security architecture

Question

Joe, the Chief Technical Officer (CTO), is concerned about new malware being introduced into the corporate network. He has tasked the security engineers to implement a technology that is capable of alerting the team when unusual traffic is on the network. Which of the following types of technologies will BEST address this scenario?

Options

  • AApplication Firewall
  • BAnomaly Based IDS
  • CProxy Firewall
  • DSignature IDS

How the community answered

(36 responses)
  • B
    92% (33)
  • C
    3% (1)
  • D
    6% (2)

Why each option

An Anomaly-Based IDS establishes a baseline of normal network behavior and alerts when traffic deviates from that baseline, making it ideal for detecting new or unusual malware activity.

AApplication Firewall

An Application Firewall controls access based on application-layer rules but does not detect or alert on unusual traffic patterns.

BAnomaly Based IDSCorrect

Anomaly-based IDS learns and profiles normal network traffic patterns and then generates alerts when observed traffic deviates significantly from that baseline. This approach is specifically designed to detect novel threats and unusual behavior that may indicate new malware, unlike signature-based systems that require known patterns.

CProxy Firewall

A Proxy Firewall mediates connections and filters content but is not designed to identify anomalous traffic indicating new malware.

DSignature IDS

A Signature-based IDS matches traffic against known attack signatures and cannot detect new or unknown malware with no existing signature.

Concept tested: Anomaly-based IDS for detecting unusual network traffic

Source: https://www.cisco.com/c/en/us/products/security/intrusion-prevention-system-ips/what-is-intrusion-prevention-system.html

Topics

#anomaly-based IDS#network monitoring#intrusion detection#malware detection

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice