hardMultiple Choice
200-201 Practice Question: A security team implements an IPS that uses…
A security team implements an IPS that uses behavioral profiling. Which type of detection method is being used?
⚠ Common exam trap
Cisco often tests the distinction between anomaly-based and heuristic detection, where candidates mistakenly choose heuristic because both involve 'behavior' or 'profiling,' but heuristic relies on predefined rules of thumb while anomaly-based relies on a learned baseline of normal behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly-based
Behavioral profiling establishes a baseline of normal network traffic patterns and then flags deviations from that baseline as potential threats. This is the core mechanism of anomaly-based detection, which identifies malicious activity by comparing observed behavior against a learned model of normal behavior rather than against predefined signatures or rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Heuristic
Why it's wrong here
Heuristic detection applies rules and scoring to identify suspicious activity, but it does not build a learned baseline of normal behaviour over time. It tempts because heuristics catch novel attacks signatures miss, yet the stem specifies behavioural profiling, which anomaly-based detection performs by comparing live activity against established norms.
- ✗
Signature-based
Why it's wrong here
Signature-based detection matches traffic against known attack patterns, so it cannot learn normal behaviour and flag deviations. It tempts because signatures reliably catch known exploits with few false positives, but behavioural profiling by definition requires a baseline of normal activity, which heuristic or anomaly detection supplies.
- ✗
Rule-based
Why it's wrong here
Behavioural profiling detects anomalies against a learned baseline of normal activity, whereas rule-based detection matches traffic to preconfigured signatures or patterns. Rule-based engines suit known-threat scenarios with stable, documented indicators, but cannot model evolving baselines, so they fail the profiling requirement in this stem.
- ✓
Anomaly-based
Why this is correct
Behavioural profiling establishes a baseline of normal activity, then flags deviations from it. Anomaly-based detection compares current events against that learned baseline, so unusual patterns trigger alerts without relying on known signatures — exactly the mechanism the stem describes.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.