exam questions

Exam PCCET All Questions

View all questions & answers for the PCCET exam

Exam PCCET topic 1 question 199 discussion

Actual exam question from Palo Alto Networks's PCCET
Question #: 199
Topic #: 1
[All PCCET Questions]

What differentiates knowledge-based systems from behavior-based systems?

  • A. Behavior-based systems find the data that knowledge-based systems store.
  • B. Knowledge-based systems pull from a previously stored database that distinguishes “bad”.
  • C. Knowledge-based systems try to find new, distinct traits to find “bad” things.
  • D. Behavior-based systems pull from a previously stored database that distinguishes “bad”.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vosicma
8 months, 2 weeks ago
Selected Answer: B
It's B
upvoted 1 times
...
darylmaeb24
1 year, 5 months ago
Selected Answer: B
seems to be the correct answer
upvoted 1 times
...
leipeG
1 year, 6 months ago
Selected Answer: B
Behavior-based systems are designed to find new and distinct traits or patterns that could indicate malicious or abnormal activity, whereas knowledge-based systems use pre-existing knowledge to make determinations.
upvoted 1 times
...
nillie
1 year, 9 months ago
Selected Answer: B
2.18.1 Differentiate between knowledge-based and behavior-based systems
upvoted 1 times
...
Blender808
1 year, 9 months ago
Selected Answer: B
Knowledge based = Signature based according to what i read. Study Guide p103 references: https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-ips https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-detection-system-ids
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago