Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security engineer is configuring a new Intrusion Detection System (IDS) to monitor network traffic for malicious activity. The engineer decides to implement a rule that triggers an alert whenever a specific, known malicious payload signature is detected within any network packet. This approach is an example of which type of security monitoring concept?
- ABehavioral-based detection
- BAnomaly-based detection
- CSignature-based detection
- DHeuristic-based detection
Show answer & explanationAnswer & explanation
Correct answer: C. Signature-based detection
Signature-based detection relies on a database of known attack patterns or 'signatures'. When the IDS detects traffic that matches one of these predefined signatures, it triggers an alert. The scenario explicitly mentions detecting a 'specific, known malicious payload signature', which is the hallmark of signature-based detection.
Why the other options are wrong
- A. Behavioral-based detection analyzes patterns of activity over time to identify suspicious behavior, not specific signatures.
- B. Anomaly-based detection identifies deviations from established baselines of normal behavior, not specific signatures.
- D. Heuristic-based detection uses rules and algorithms to identify potential threats, often without a specific signature match, similar to anomaly but often more rule-driven.
Signature-based Detection
A method of detecting threats by comparing observed data (e.g., network traffic, file content) against a database of known malicious patterns or signatures.
- Effective against known threats.
- Requires frequent updates to the signature database.
- Ineffective against zero-day attacks or polymorphic malware.
Memory trick: IDS: Signatures are Known, Anomalies are Unknown.