ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A security analyst is reviewing network traffic logs and notices an unusual number of failed login attempts originating from an external IP address trying to access the internal HR portal. This activity is inconsistent with normal user behavior. Which security monitoring technique is the analyst employing?

  1. ABaseline analysis
  2. BBehavioral anomaly detection
  3. CHeuristic analysis
  4. DSignature-based detection
Show answer & explanation

Correct answer: B. Behavioral anomaly detection

Behavioral anomaly detection identifies deviations from established normal patterns of behavior. In this scenario, 'unusual number of failed login attempts' and 'inconsistent with normal user behavior' directly indicate the use of this technique.

Why the other options are wrong

  • A. Baseline analysis is part of establishing 'normal' behavior, but the *detection* of the deviation is behavioral anomaly detection.
  • C. Heuristic analysis uses rules and algorithms to identify suspicious activity, which can be part of anomaly detection, but 'behavioral anomaly detection' is the more specific and accurate term here.
  • D. Signature-based detection looks for known attack patterns; this scenario describes an *unusual behavior*, not necessarily a known signature.

Behavioral Anomaly Detection

A security monitoring technique that identifies deviations from established normal patterns of user or system behavior, signaling potential security incidents.

  • Learns 'normal' behavior over time.
  • Can detect novel or zero-day attacks.
  • Often results in a higher rate of false positives.

Memory trick: Anomalies are the red flags, signatures are the wanted posters.

More Security Operations questions