ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy
A CISA is auditing an organization's network security, specifically its intrusion detection system (IDS). The IDS is primarily signature-based. Recently, the organization experienced a breach that involved a novel zero-day exploit for which no known signatures existed. What is the MOST significant limitation of a purely signature-based IDS highlighted by this incident?
- AInability to detect previously unknown or zero-day attacks.
- BHigh rate of false positives from legitimate network traffic.
- CSignificant performance overhead on network devices.
- DDifficulty in updating signature databases in a timely manner.
Show answer & explanationAnswer & explanation
Correct answer: A. Inability to detect previously unknown or zero-day attacks.
Signature-based IDSs rely on known patterns of attack. By definition, a zero-day exploit is a novel attack for which no signature exists. Therefore, a purely signature-based IDS will fail to detect such an attack, which is its most significant limitation.
Why the other options are wrong
- B. False positives are a general IDS challenge, but not the primary limitation when discussing zero-day exploits.
- C. Performance overhead can be an issue, but it's not directly related to the detection of unknown threats.
- D. Timely updates are important, but even with instant updates, a zero-day exploit would still be undetectable until a signature is created.
Signature-Based IDS Limitations
The inherent weaknesses of intrusion detection systems that rely solely on predefined attack patterns (signatures), particularly their inability to detect novel or zero-day threats.
- Effective against known threats.
- Ineffective against unknown or polymorphic attacks.
- Requires constant updates to signature databases.
Memory trick: A detective with a mugshot can find a known criminal, but not a ghost.