Certified Information Systems Security Professional CISSP · Free Practice Question Hard
Question 83
You are a cybersecurity consultant hired by a multinational corporation to strengthen its security posture. After conducting a network security audit, you discover that the current security infrastructure fails to detect deviations from normal network behavior, which could indicate potential insider threats or zero-day attacks. Which of the following detection methods would you recommend to effectively identify unusual activities that deviate from normal network traffic patterns?
- A Signature-based detection.
- B Behavior-based detection.
- C Misuse detection.
- D Rule-based detection.
Reveal correct answer
Correct answer: B
Explanation
OBJ. 7.2 - Behavior-based detection focuses on identifying deviations from normal patterns of network behavior, making it highly effective at detecting insider threats and zero-day attacks, which may not be recognizable by signatures. Signature-based detection relies on known attack patterns, and rule-based or misuse detection methods are less effective at identifying previously unknown threats that exhibit anomalous behavior. Behavior-based detection is, therefore the best option for detecting unknown or unexpected threats. For support or reporting issues, include Question ID: 67d9694ceac84fca71b27ec8 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
