ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is auditing an organization's network security, specifically its intrusion detection system (IDS). The IDS is primarily signature-based. Recently, the organization experienced a breach that involved a novel zero-day exploit for which no known signatures existed. What is the MOST significant limitation of a purely signature-based IDS highlighted by this incident?

  1. AInability to detect previously unknown or zero-day attacks.
  2. BHigh rate of false positives from legitimate network traffic.
  3. CSignificant performance overhead on network devices.
  4. DDifficulty in updating signature databases in a timely manner.
Show answer & explanation

Correct answer: A. Inability to detect previously unknown or zero-day attacks.

Signature-based IDSs rely on known patterns of attack. By definition, a zero-day exploit is a novel attack for which no signature exists. Therefore, a purely signature-based IDS will fail to detect such an attack, which is its most significant limitation.

Why the other options are wrong

  • B. False positives are a general IDS challenge, but not the primary limitation when discussing zero-day exploits.
  • C. Performance overhead can be an issue, but it's not directly related to the detection of unknown threats.
  • D. Timely updates are important, but even with instant updates, a zero-day exploit would still be undetectable until a signature is created.

Signature-Based IDS Limitations

The inherent weaknesses of intrusion detection systems that rely solely on predefined attack patterns (signatures), particularly their inability to detect novel or zero-day threats.

  • Effective against known threats.
  • Ineffective against unknown or polymorphic attacks.
  • Requires constant updates to signature databases.

Memory trick: A detective with a mugshot can find a known criminal, but not a ghost.

More Domain 5: Protection of Information Assets questions