Which statement describes the policy-based intrusion detection approach?

IT Exam Items RepositoryCategory: CCNA CyberOpsWhich statement describes the policy-based intrusion detection approach?

Which statement describes the policy-based intrusion detection approach?

  • It compares the signatures of incoming traffic to a known intrusion database.
  • It compares the operations of a host against well-defined security rules.
  • It compares the antimalware definitions to a central repository for the latest updates.
  • It compares the behaviors of a host to an established baseline to identify potential intrusion.

Explanation: With the anomaly-based intrusion detection approach, a set of rules or policies are applied to a host. Violation of these policies is interpreted to be the result of a potential intrusion.

Related exam: Checkpoint Exam: Cryptography and Endpoint Protection Group Exam
Related exam: CCNA Cyber Ops Final Exam Answers
Related exam: Endpoint Security - OS and Endpoint Security Checkpoint Exam Answers
Related exam: Cybersecurity Essentials - Checkpoint Exam: OS and Endpoint Security (Module 7 – 10 Exam)
Related exam: Endpoint Security: My Knowledge Check Answers