Systems Security Certified Practitioner – SSCP – Question0439

Which of the following is an IDS that acquires data and defines a "normal" usage profile for the network or host?

A.
Statistical Anomaly-Based ID
B. Signature-Based ID
C. dynamical anomaly-based ID
D. inferential anomaly-based ID

Correct Answer: A

Explanation:

Statistical Anomaly-Based ID -With this method, an IDS acquires data and defines a “normal” usage profile for the network or host that is being monitored. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 49.