Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A security team is implementing a new intrusion detection system (IDS). Before deploying it to the production network, they want to ensure it effectively identifies malicious traffic patterns without generating excessive false positives. They decide to deploy the IDS in a passive 'tap' mode for a period, collecting alerts and comparing them against known legitimate and malicious activities. Which phase of the security operations lifecycle does this activity primarily fall under?
- ADetect
- BRespond
- CPrevent
- DRecover
Show answer & explanationAnswer & explanation
Correct answer: A. Detect
Deploying an IDS in passive mode to identify malicious traffic patterns is a detection activity. The team is gathering information to understand what needs to be detected effectively.
Why the other options are wrong
- B. Respond involves actions taken after an incident is detected, such as containment and eradication.
- C. Prevent involves proactive measures to stop attacks, which is not the primary goal of passively monitoring an IDS.
- D. Recover focuses on restoring systems and data to normal operations after an incident.
Security Operations Lifecycle - Detect
The phase in security operations focused on identifying security incidents, anomalies, and potential threats through continuous monitoring, logging, and analysis.
- Involves tools like IDS/IPS, SIEM, and endpoint detection.
- Aims to identify malicious activity as early as possible.
- Requires baseline understanding of normal network behavior.
Memory trick: Prevent, Detect, Respond, Recover; a cycle for security to discover.