ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is evaluating an organization's network security, specifically its intrusion detection system (IDS). The CISA notes that the IDS is configured to only detect known attack signatures and is not updated frequently. Furthermore, no intrusion prevention system (IPS) is in place. What is the MOST significant limitation of this setup?
- ALack of real-time blocking of malicious traffic.
- BHigh rate of false positives due to signature-based detection.
- CInsufficient coverage across the entire network infrastructure.
- DInability to detect novel or zero-day attacks.
Show answer & explanationAnswer & explanation
Correct answer: D. Inability to detect novel or zero-day attacks.
A signature-based IDS that is not frequently updated can only detect known attack patterns. It will be ineffective against novel, polymorphic, or zero-day attacks that do not match existing signatures, leaving the organization vulnerable to new threats.
Why the other options are wrong
- A. This is a limitation of *not having an IPS*, but the question also highlights issues with the IDS itself (signature-based, not updated).
- B. Signature-based systems generally have lower false positive rates compared to anomaly-based systems, though outdated signatures can lead to missed detections.
- C. While coverage is important, the core limitation described (signature-based, not updated) is about the *type* of threats it can detect, not its deployment scope.
Signature-Based IDS Limitations
Intrusion detection systems that rely on matching traffic patterns to known attack signatures, making them ineffective against new or unknown threats.
- Effective against known attack patterns.
- Requires frequent signature updates to remain effective.
- Cannot detect zero-day or novel attacks.
Memory trick: The old wanted poster only catches known bandits, not the new, hidden ghosts.