Question 520:
Which of the following assertions is NOT true about pattern matching and anomaly detection in intrusion detection?
Answer options:
A. Anomaly detection tends to produce more data B. A pattern matching IDS can only identify known attacks C. Stateful matching scans for attack signatures by analyzing individual packets instead of traffic streams D. An anomaly-based engine develops baselines of normal traffic activity and throughput, and alerts on deviations from these baselines