ISC Systems Security Certified Practitioner SSCP Question # 72 Topic 8 Discussion

ISC Systems Security Certified Practitioner SSCP Question # 72 Topic 8 Discussion

SSCP Exam Topic 8 Question 72 Discussion:
Question #: 72
Topic #: 8

Which of the following best describes signature-based detection?


A.

Compare source code, looking for events or sets of events that could cause damage to a system or network.


B.

Compare system activity for the behaviour patterns of new attacks.


C.

Compare system activity, looking for events or sets of events that match a predefined pattern of events that describe a known attack.


D.

Compare network nodes looking for objects or sets of objects that match a predefined pattern of objects that may describe a known attack.


Get Premium SSCP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.