exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 21 discussion

Actual exam question from Cisco's 200-201
Question #: 21
Topic #: 1
[All 200-201 Questions]

What is the difference between statistical detection and rule-based detection models?

  • A. Rule-based detection involves the collection of data in relation to the behavior of legitimate users over a period of time
  • B. Statistical detection defines legitimate data of users over a period of time and rule-based detection defines it on an IF/THEN basis
  • C. Statistical detection involves the evaluation of an object on its intended actions before it executes that behavior
  • D. Rule-based detection defines legitimate data of users over a period of time and statistical detection defines it on an IF/THEN basis
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Leo_Visser
Highly Voted 2 years, 11 months ago
B is correct. Statistical checks over a period of time to see if it adheres to certain trends. Rulebased just checks for this specific moment.
upvoted 9 times
...
WISDOM2080
Most Recent 8 months, 2 weeks ago
A. Threat represents a potential danger that could take advantage of a weakness, while the risk is the likelihood of a compromise or damage of an asset.
upvoted 1 times
...
WISDOM2080
8 months, 2 weeks ago
B. Statistical detection defines legitimate data of users over a period of time and rule-based detection defines it on an IF/THEN basis
upvoted 1 times
...
alhamry
1 year ago
The answer is B. Statistical detection models use mathematical algorithms to define normal user behavior over a period of time, and deviations from this behavior are flagged as potential threats. Rule-based detection models, on the other hand, use a predefined set of rules to identify specific patterns or signatures of known attacks. Rule-based detection models operate on an IF/THEN basis, where if a certain condition is met, a threat is flagged.
upvoted 1 times
...
drdecker100
1 year, 2 months ago
Selected Answer: B
Rule-based detection models use a predefined set of rules to determine whether a particular behavior is normal or anomalous. These rules are typically based on the expected behavior of legitimate users, and are often expressed in an "if-then" format. For example, a rule-based system might flag any attempt to log in to a particular application from an unusual IP address as potentially suspicious. Statistical detection models, on the other hand, use statistical analysis to identify patterns of behavior that deviate from the norm. These models are often based on machine learning algorithms that analyze large amounts of data to identify normal behavior and then flag any activity that deviates from that norm as potentially suspicious. For example, a statistical detection model might flag any attempt to transfer an unusually large amount of data from a particular user account as potentially suspicious.
upvoted 1 times
...
hansamaru
1 year, 6 months ago
Agreed for B
upvoted 1 times
...
halamah
2 years, 6 months ago
B IS CORRECT STATIC OVER PERIOD OF TIME RULE BASED IDENTIFY POTENTIAL attack
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago