312-49 Exam QuestionsBrowse all questions from this exam

312-49 Exam - Question 31


Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

Show Answer
Correct Answer: C

Anomaly detection typically produces the most false alarms. It works by identifying deviations from a baseline of normal behavior, which can be highly variable and unpredictable due to diverse activities of users and networks. This variability often leads to false positives, unlike more deterministic methods such as signature recognition.

Discussion

7 comments
Sign in to comment
PetOption: C
Jun 15, 2019

Answer shd be C. anomaly detection

W3bhakrOption: C
Feb 6, 2020

According to http://techgenix.com/ids-part2-classification-methods-techniques/ the answer should be C

HumptydumtyyOption: B
Dec 10, 2020

B is correct. The answer is in the question. users + network. anomaly detection is not a type of IDS

simontkk2005
Apr 30, 2019

Answer is B + C

ireenOption: B
Aug 25, 2019

I believe “anomaly detection” is a feature not a type of ids. And in question (users and networks) are mentioned. So imho answer should be B

Ceh2024Option: C
Sep 3, 2023

out-of-the-ordinary behavior does not mean that it's 100% malicious. So the most false alarm will be happened on the anomaly detection IDS

Bennoli13Option: C
Jun 13, 2024

Among the given options, anomaly detection systems typically produce the most false alarms. This is because anomaly detection systems work by identifying deviations from a baseline of normal behavior, which can be highly variable and unpredictable due to the diverse activities of users and networks. While both network-based IDS (NIDS) and host-based IDS (HIDS) can employ anomaly detection methods, it is the specific approach of anomaly detection itself that tends to generate a higher rate of false positives compared to signature-based detection methods, which rely on known patterns of malicious behavior.