Certified Information Systems Auditor CISA · Free Practice Question Medium
Question 42
You are auditing HDA Inc. as an information system auditor, and your task is to evaluate the effectiveness of signature-based intrusion detection systems (IDS). In this context, what would be the most reliable indicator of their effectiveness?
- A A. Low system downtime during an attack
- B B. High number of alerts which were not previously identified
- C C. Regular software updates on the IDS
- D D. Compliance with industry standards for IDS implementation
Reveal correct answer
Correct answer: B
Explanation
Correct Answer: B. High number of alerts which were not previously identified Explanation: Signature-based intrusion detection systems (IDS) rely on a database of known attack patterns or signatures to identify potential security threats. The effectiveness of such systems can be evaluated based on the number of alerts generated that were not previously identified or recognized by the IDS. When the IDS detects a high number of alerts that were not previously identified, it suggests that the system is successfully detecting new or unknown threats. This indicates that the IDS is effectively matching the detected network traffic or system behavior against its signature database, identifying potential attacks or malicious activities that were not previously known or accounted for. Option A, low system downtime during an attack, is not the best indicator of the effectiveness of signature-based IDS. While low system downtime is desirable, it may be influenced by other factors such as system resilience, network architecture, or incident response procedures, rather than solely relying on the IDS. Option C, regular software updates on the IDS, is important for maintaining the security and functionality of the IDS but does not directly indicate its effectiveness in detecting attacks. Regular updates are necessary to keep the signature database up to date with the latest attack patterns, but this alone does not guarantee the effectiveness of the IDS. Option D, compliance with industry standards for IDS implementation, is important for ensuring a baseline level of security, but it does not provide a direct measure of the IDS's effectiveness. Compliance with standards focuses on the implementation and configuration of the IDS, rather than its actual performance in detecting attacks. In conclusion, the best indicator of the effectiveness of signature-based intrusion detection systems is a high number of alerts that were not previously identified. This indicates the system's capability to detect new or unknown threats based on its signature database, contributing to a proactive and effective security posture.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
