CompTIA Security+ Exam Prep

Category - Operations

Kim wants to know of any differences in the baseline environment of her system by learning of any changes in the amount of activity in the system. What would be her best option?
  1. Traffic Anomaly-based IDS
  2. Network Sniffers
  3. Network-based Detection
  4. Host-based Detection
Explanation
Answer: A - To learn of any differences in the baseline environment of a system by detecting any changes in the amount of activity in the system would best be obtained by using a traffic anomaly-based IDS. Most behavioral-based IDSs have traffic anomaly-based filters, which detect changes in traffic patterns. Once a profile is built that captures the baselines of an environment’s ordinary traffic, all future traffic patterns are compared to that profile. As with all filters, the thresholds are tunable to adjust the sensitivity and to reduce the number of false positives and false negatives. Since this is a type of statistical anomaly-based IDS, it can detect unknown attacks.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz