Study. uk . com
  1. Home
  2. All questions
  3. Question 388

CompTIA Security+ study material · question 388 of 611

A team wants detection that can catch previously unseen attack behaviour and accepts more investigation effort. Which approach fits?

  1. Signature-based detection
  2. Anomaly-based detection
  3. DNS filtering
  4. Allow-listing
Show the answer

Answer: B. Anomaly-based detection

Anomaly detection can flag the novel case at the cost of more false positives; signatures need the pattern to be known.

Challenge yourself on this topic → Study as cards