Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?
The anomaly-based intrusion detection system (IDS) monitors network traffic and compares it against an established baseline. This type of IDS
monitors traffic and system activity for unusual behavior based on statistics. In order to identify a malicious activity, it learns normal behavior
from the baseline. The anomaly-based intrusion detection is also known as behavior-based or statistical-based intrusion detection.
Answer D is incorrect. Signature-based IDS uses a database with signatures to identify possible attacks and malicious activity.
Answer B is incorrect. A network-based IDS can be a dedicated hardware appliance, or an application running on a computer, attached
to the network. It monitors all traffic in a network or traffic coming through an entry-point such as an Internet connection.
Answer A is incorrect. There is no such intrusion detection system (IDS) that is file-based.
Alease
6 months agoDomonique
6 months agoSage
7 months agoAja
7 months agoDolores
7 months agoAmmie
8 months agoProvidencia
8 months agoVivienne
8 months agoHollis
8 months agoChau
8 months agoNoe
9 months agoClay
9 months agoIvory
9 months agoBettina
9 months agoLashandra
10 months agoTijuana
10 months agoSamira
10 months agoFloyd
6 months agoHillary
6 months agoNoah
7 months agoTarra
7 months agoAmmie
11 months agoIvette
11 months agoLili
11 months agoTawny
10 months agoParis
10 months agoDulce
10 months ago