Courseiva
hardMultiple Choice

200-201 Practice Question: A security team implements an IPS that uses…

A security team implements an IPS that uses behavioral profiling. Which type of detection method is being used?

⚠ Common exam trap

Cisco often tests the distinction between anomaly-based and heuristic detection, where candidates mistakenly choose heuristic because both involve 'behavior' or 'profiling,' but heuristic relies on predefined rules of thumb while anomaly-based relies on a learned baseline of normal behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly-based

Behavioral profiling establishes a baseline of normal network traffic patterns and then flags deviations from that baseline as potential threats. This is the core mechanism of anomaly-based detection, which identifies malicious activity by comparing observed behavior against a learned model of normal behavior rather than against predefined signatures or rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Heuristic

    Why it's wrong here

    Heuristic detection applies rules and scoring to identify suspicious activity, but it does not build a learned baseline of normal behaviour over time. It tempts because heuristics catch novel attacks signatures miss, yet the stem specifies behavioural profiling, which anomaly-based detection performs by comparing live activity against established norms.

  • ✗

    Signature-based

    Why it's wrong here

    Signature-based detection matches traffic against known attack patterns, so it cannot learn normal behaviour and flag deviations. It tempts because signatures reliably catch known exploits with few false positives, but behavioural profiling by definition requires a baseline of normal activity, which heuristic or anomaly detection supplies.

  • ✗

    Rule-based

    Why it's wrong here

    Behavioural profiling detects anomalies against a learned baseline of normal activity, whereas rule-based detection matches traffic to preconfigured signatures or patterns. Rule-based engines suit known-threat scenarios with stable, documented indicators, but cannot model evolving baselines, so they fail the profiling requirement in this stem.

  • ✓

    Anomaly-based

    Why this is correct

    Behavioural profiling establishes a baseline of normal activity, then flags deviations from it. Anomaly-based detection compares current events against that learned baseline, so unusual patterns trigger alerts without relying on known signatures — exactly the mechanism the stem describes.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.