CompTIA Security+ Exam Prep

Category - Operations

What is a behavior-based system that learns to build a profile of an environment’s “normal” activities?
  1. Statistical anomaly-based IDS
  2. Intrusion Detection
  3. Network-based Detection
  4. Host-based Detection
Explanation
Answer: A - Statistical anomaly-based IDS is a behavior-based system that learns to build a profile of an environment’s “normal” activities. Behavior-based IDS products do not use predefined signatures, but rather are put in a learning mode to build a profile to determine what is “normal.” This profile is built by continually sampling the environment’s activities. The longer the IDS is put in a learning mode, the more accurate a profile it will build and the better protection is will provide. After this profile is built, all future traffic and activities are compared to it. Ultimately, this system knows when it is being attacked.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz