MCQs City stays free thanks to ads. Please turn off your ad blocker for this site so content and features keep working.
Computer Networks
Entrance Exams
Q
Which of the following is an advantage of anomaly detection?
AA. Rules are easy to define
BB. Custom protocols can be easily analyzed
CC. The engine can scale as the rule set grows
DD. Malicious activity that falls within normal usage patterns is detected
Correct Answer:
C. C. The engine can scale as the rule set grows
Explanation:
Once a protocol has been built and a behavior defined, the engine can scale more quickly and easily than the signature-based model because a new signature does not have to be created for every attack and potential variant.