ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

A managed security service provider (MSSP) is onboarding a new client with a complex network infrastructure. As part of the initial assessment, the MSSP needs to establish a baseline of normal network behavior and traffic patterns to effectively detect anomalies and potential threats. Which of the following activities is MOST critical for establishing this baseline?

  1. AConducting a comprehensive vulnerability scan of all internal systems.
  2. BCollecting and analyzing network flow data (e.g., NetFlow, IPFIX) over a period of time.
  3. CDeploying a honeypot to attract and analyze attacker techniques.
  4. DPerforming an external penetration test against the client's public-facing assets.
Show answer & explanation

Correct answer: B. Collecting and analyzing network flow data (e.g., NetFlow, IPFIX) over a period of time.

Collecting and analyzing network flow data (like NetFlow or IPFIX) over a significant period is crucial for establishing a baseline of normal network behavior. This data provides insights into who is communicating with whom, over which ports, and how much data is being transferred, allowing for the detection of deviations that indicate anomalies or threats.

Why the other options are wrong

  • A. Vulnerability scanning identifies system weaknesses, but it does not provide insight into network traffic patterns or establish a behavioral baseline.
  • C. A honeypot is for attracting and studying attackers, not for establishing a baseline of *normal* network behavior.
  • D. Penetration testing identifies existing vulnerabilities but does not establish a baseline of day-to-day network traffic and behavior for anomaly detection.

Network Baslining

Network baselining is the process of capturing and analyzing network performance and traffic data over a period to establish a 'normal' operational state. This baseline is then used to detect deviations that may indicate performance issues, security incidents, or policy violations.

  • Identifies normal traffic patterns and volumes.
  • Crucial for anomaly detection and security monitoring.
  • Requires data collection over time to account for variations.
  • Often involves network flow data (NetFlow, sFlow, IPFIX).

Memory trick: Know what's normal to spot the abnormal.

More Security Operations questions