Q: 1
Which of the following options represents a conceptual characteristic of an anomaly-based IDS over
a signature-based IDS?
Options
Discussion
Probably B, official guide and some labs talk about anomaly-based picking up unknown attack types.
B , main thing with anomaly-based IDS is it can spot stuff that hasn't been seen before, like new attack patterns. Signature-based is stuck with what's in its database. Pretty sure that's the key difference here.
Definitely B here. Anomaly-based IDS is designed to flag things that don't match normal behavior, so it can catch zero-day or unknown attacks. Signature-based only works with known patterns. Pretty sure that's what they're looking for, but open to other takes.
It’s B for sure
Its B since anomaly-based IDS can spot new or unknown attacks by looking for anything outside the usual behavior. Signature-based needs known patterns so it usually misses zero-days. Not totally sure every scenario but this is the main difference as I understand it. Anyone got a counterpoint?
B, that lines up with what I've seen in other practice sets. Nice and clear wording here.
Be respectful. No spam.
Question 1 of 35