ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium
A managed security service provider (MSSP) is onboarding a new client with a complex network infrastructure. To effectively monitor for anomalies and potential threats, the MSSP's first step is to collect network traffic data over a period of time to establish expected behavior patterns. What is this process called?
- APenetration Testing
- BVulnerability Assessment
- CThreat Hunting
- DNetwork Baselining
Show answer & explanationAnswer & explanation
Correct answer: D. Network Baselining
Network baselining involves establishing a performance baseline for the network and its devices under normal operating conditions. This baseline is then used as a reference point to detect deviations that could indicate a security incident or performance issue.
Why the other options are wrong
- A. Penetration Testing actively exploits vulnerabilities to identify security weaknesses, which is different from observing normal behavior.
- B. Vulnerability Assessment identifies weaknesses in systems or applications, not normal network traffic patterns.
- C. Threat Hunting is proactively searching for threats that have evaded existing security controls, not establishing normal behavior.
Network Baselining
Network baselining is the process of measuring and recording the normal performance and behavior of a network over a period of time to establish a reference point for future comparisons and anomaly detection.
- Establishes 'normal' operational patterns.
- Used to detect deviations and anomalies.
- Crucial for effective monitoring and incident detection.
Memory trick: Baseline is the 'base' of what's normal, where anomalies stand out.