Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security team is implementing a new endpoint detection and response (EDR) solution. As part of its advanced threat detection capabilities, the EDR system is configured to continuously monitor user and system activities on endpoints, looking for deviations from established baselines or known normal patterns. For example, it might flag an unusual executable launching from a temporary directory and attempting to connect to a suspicious external IP address. Which security monitoring concept is primarily being utilized by this EDR feature?
- ASignature-based Detection
- BVulnerability Scanning
- CLog Aggregation
- DBehavioral Analysis
Show answer & explanationAnswer & explanation
Correct answer: D. Behavioral Analysis
Behavioral analysis focuses on monitoring and analyzing user and system activities to identify deviations from normal or expected patterns. This allows for the detection of unknown or 'zero-day' threats that might not have a known signature.
Why the other options are wrong
- A. Signature-based detection relies on known attack patterns, not deviations from normal behavior.
- B. Vulnerability scanning identifies weaknesses, not active malicious behavior.
- C. Log aggregation collects logs, but the analysis of 'deviations from baselines' is behavioral analysis.
Behavioral Analysis
A security monitoring concept that involves observing and analyzing the actions and patterns of users, systems, and applications to detect anomalies or deviations from established baselines of normal behavior, thereby identifying potential threats or malicious activities.
- Effective against zero-day threats and polymorphic malware.
- Requires establishing a baseline of normal activity.
- Can generate more false positives than signature-based methods.
Memory trick: Behavioral analysis is like teaching a guard what 'normal' looks like, so they can spot anything 'abnormal'.