Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 57 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 57
Topic #: 1
[All 312-49v10 Questions]

Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?

  • A. network-based IDS systems (NIDS)
  • B. host-based IDS systems (HIDS)
  • C. anomaly detection
  • D. signature recognition
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
claudiatang9
Highly Voted 2 years, 1 month ago
Might be C. CHFI textbook p651: the conventional method of anomaly detection, essential data are kept for checking variations in network traffic. However, in reality, some unpredictability exists in network traffic, and there are too many statistical variations, making these models imprecise. Some events labeled as anomalies might only be irregularities in network usage.
upvoted 5 times
...
Toni222
Most Recent 4 months, 2 weeks ago
Selected Answer: C
Anomaly detection systems typically produce the most false alarms because they are designed to identify deviations from normal behavior. Since user and network behaviors can be unpredictable and varied, these systems may incorrectly flag legitimate activities as suspicious, leading to a higher number of false positives.
upvoted 2 times
...
Elb
5 months, 2 weeks ago
Selected Answer: A
NIDS systems turn up more false positives than HIDS.
upvoted 1 times
...
Elb
1 year, 4 months ago
I think B is the correct answer. Question ask for the IDS systems ( hids/nids) not for the IDS detection approach ( Anomaly/Signature)
upvoted 1 times
Elb
1 year, 4 months ago
A not B. :) NIDS is quicker but turn up more false positives than an HIDS.
upvoted 1 times
...
...
Port_Stack
1 year, 11 months ago
The question itself mentions users and networks, hence it cannot be HIDS as that is limited to Host. It narrows it down to NIDS or Anomaly Detection. The details for Anomaly Detection is found in EC Coucil's Network Defender Course e-Book where it states the following disadvantages for Anomaly Detection. "Disadvantages ▪ The rate of generating false alarms is high due to unpredictable behavior of users and networks ▪ The need to create an extensive set of system events in order to characterize normal behavior patterns" The answer should be Anomaly Detection.
upvoted 3 times
...
BarryMacockener
2 years ago
I feel like the answer has to be either B or C as the question specifically refers to the "unpredictable behavior" of users. It's definitely NOT D, as a signature-based IDS is not behavior-based as it looks for predefined characteristics. It's pretty well-known in infosec that a signature-based IDS does not produce as many false positives as an anomaly-based IDS. I personally believe the answer is C.
upvoted 3 times
...
vcloudpmp
2 years, 8 months ago
Might be D. From EC Council official materials: " Signature recognition can detect known attacks. However, there is a possibility that some innocuous packets might also contain the same signature, triggering false positives. o Improper signatures may trigger false positives. To detect misuse, a huge number of signatures is required. The more the signatures, the greater are the chances of the IDS detecting attacks. However, normal traffic may incorrectly match with the signatures, impeding system performance.
upvoted 2 times
...
K3nz0420
2 years, 9 months ago
Network based IDS should be the correct answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...