ISC2 Certified in Cybersecurity (CC)Security OperationsEasy
A security analyst is reviewing network traffic logs and notices an unusual number of failed login attempts to a critical server from an external IP address. This activity occurs outside of business hours and is not associated with any known legitimate remote access. Which of the following security monitoring activities is being performed?
- APenetration testing
- BSecurity auditing
- CAnomaly detection
- DVulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: C. Anomaly detection
Anomaly detection involves identifying patterns or behaviors that deviate significantly from the established baseline of normal activity, indicating potential security incidents.
Why the other options are wrong
- A. Penetration testing is an active, authorized simulation of an attack, not passive monitoring.
- B. Security auditing involves reviewing controls and compliance, not real-time unusual activity detection.
- D. Vulnerability scanning identifies weaknesses in systems, not unusual network activity patterns.
Anomaly Detection
The process of identifying patterns or behaviors in data that are significantly different from the expected or normal patterns, often indicating potential security threats or system issues.
- Identifies deviations from a baseline
- Can detect novel attacks or insider threats
- Requires establishing a 'normal' behavior profile
Memory trick: Monitoring for the 'odd one out' is key to security.