Which of the following is a limitation of intrusion detection systems?

Prepare for the EC-Council Certified Security Specialist Exam with our comprehensive quiz. Enhance your understanding through flashcards and multiple-choice questions complete with hints and explanations. Boost your exam confidence today!

Multiple Choice

Which of the following is a limitation of intrusion detection systems?

Explanation:
Attackers continually evolve, and that creates a fundamental limitation for intrusion detection systems. Even when signatures are updated and new detection methods are developed, clever adversaries find ways to bypass them—through novel attack techniques, obfuscated payloads, encrypted or low-and-slow traffic, or exploiting unknown vulnerabilities. Because IDS often rely on known signatures or established baselines of normal behavior, there will always be methods that slip through until detection models are updated, making zero-day and sophisticated evasion a persistent challenge. The other ideas describe activities that are part of maintaining or improving IDS or are simply inaccurate (for example, logging is a normal capability, and IDS is not immune to false positives).

Attackers continually evolve, and that creates a fundamental limitation for intrusion detection systems. Even when signatures are updated and new detection methods are developed, clever adversaries find ways to bypass them—through novel attack techniques, obfuscated payloads, encrypted or low-and-slow traffic, or exploiting unknown vulnerabilities. Because IDS often rely on known signatures or established baselines of normal behavior, there will always be methods that slip through until detection models are updated, making zero-day and sophisticated evasion a persistent challenge. The other ideas describe activities that are part of maintaining or improving IDS or are simply inaccurate (for example, logging is a normal capability, and IDS is not immune to false positives).

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy