Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security team is implementing a new Intrusion Prevention System (IPS) to protect the corporate network. The IPS is configured to block traffic based on known malicious patterns and signatures. Which detection method is this IPS primarily employing?
- ABehavioral-based Detection
- BAnomaly-based Detection
- CHeuristic-based Detection
- DSignature-based Detection
Show answer & explanationAnswer & explanation
Correct answer: D. Signature-based Detection
The IPS is configured to block traffic based on 'known malicious patterns and signatures'. This is the definition of signature-based detection, where the system compares network traffic or system activity against a database of known attack signatures.
Why the other options are wrong
- A. Behavioral-based detection is a subset of anomaly detection, focusing on user or system behavior.
- B. Anomaly-based detection identifies deviations from established baselines of normal behavior.
- C. Heuristic-based detection uses rules and algorithms to identify suspicious activity that might indicate an unknown threat.
Signature-based Detection
A method of intrusion detection that identifies threats by comparing network traffic or system activity against a database of known attack patterns, or signatures.
- Effective at detecting known threats with high accuracy.
- Prone to false negatives for new or unknown attacks (zero-day exploits).
- Requires frequent updates to the signature database.
- Widely used in antivirus software and intrusion detection/prevention systems (IDS/IPS).
Memory trick: Signatures Spot Known Anomalies