CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 391


Which of the following is the BEST indicator of the effectiveness of signature-based intrusion detection systems (IDSs)?

Show Answer
Correct Answer: D

The best indicator of the effectiveness of signature-based intrusion detection systems (IDSs) is an increase in the number of detected incidents not previously identified. Signature-based IDSs work by comparing the activity against known attack signatures. Thus, an increase in the number of detected incidents implies that the system is effectively identifying threats based on its database of known attack patterns.

Discussion

6 comments
Sign in to comment
starzuuOption: C
Aug 3, 2023

D is also not correct because signature based IDS is not Heuristic IDS meaning it can only indicate KNOWN malicious activities.

AB1237Option: A
Sep 9, 2023

Isnt it A? Increase in no. of internally reported critical incidents? Since signature based IDS consists of pre fed information about what attacks to look out for, and this option address that?

SwallowsOption: D
Jun 8, 2024

Signature-based intrusion detection systems work by comparing network traffic or system activity against a database of known attack signatures or patterns. The primary goal is to detect and alert on known threats based on predefined signatures.

DeeplaxmiOption: D
Oct 2, 2022

D- increase in number of DETECTED but not previously identified incidents is correct

MohamedAbdelaal
Apr 16, 2023

hhhhh You got all the right

a84nOption: C
Apr 28, 2024

Answer C. An increase in the number of identified false positives indicates that the IDS is actively detecting and flagging potential threats based on known signatures.

topikalOption: D
Jun 19, 2024

tricky wording but the right answer is D