Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security team is implementing a new endpoint detection and response (EDR) solution. The EDR is configured to collect data on normal user behavior, process execution, and network connections. It then uses this baseline to identify unusual activities that deviate significantly from the established norms. What type of detection method is the EDR primarily employing?

  1. AHeuristic-based Detection
  2. BSignature-based Detection
  3. CRule-based Detection
  4. DAnomaly-based Detection
Show answer & explanation

Correct answer: D. Anomaly-based Detection

Anomaly-based detection (or behavioral analysis) establishes a baseline of normal activity and flags any deviations from that baseline as potentially malicious. The scenario explicitly mentions collecting data on 'normal user behavior' and identifying 'unusual activities that deviate significantly from the established norms'.

Why the other options are wrong

  • A. Heuristic-based detection uses algorithms and expert systems to identify new threats based on suspicious characteristics, which can overlap with anomaly detection but is broader and less focused on a 'baseline'.
  • B. Signature-based detection relies on known patterns or signatures of malware, not deviations from a baseline.
  • C. Rule-based detection uses predefined rules to identify threats, which is less flexible than baseline deviations.

Anomaly-based Detection

A security detection method that establishes a baseline of normal system or user behavior and then identifies deviations from this baseline as potential security incidents. It is effective at detecting unknown or zero-day threats that do not have existing signatures.

  • Builds a baseline of 'normal'.
  • Flags deviations from the baseline.
  • Effective against unknown/zero-day threats.
  • Can generate false positives.

Memory trick: Anomaly detection is like noticing your cat suddenly wearing a tiny hat.

More Security Concepts questions