Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
Which of the following best describes signature-based detection?
Correct Answer: C
Explanation/Reference: Explanation: Models of how the attacks are carried out are developed and called signatures. Each identified attack has a signature, which is used to detect an attack in progress or determine if one has occurred within the network. Any action that is not recognized as an attack is considered acceptable. Incorrect Answers: A: Signature-based detection checks activities and events. It does check source codes. B: Signature-based detection checks for patterns of old known attacks. It does not check for new unknown patterns of attacks. D: Signature-based detection monitors activities and events, not objects. References: Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 257