A network administrator is configuring an intrusion prevention system (IPS) and needs to understand how signature-based and anomaly-based detection engines operate. Which TWO statements accurately describe anomaly-based IPS detection? (Choose two)
Anomaly detection builds a behavioral baseline and flags deviations.
Why this answer
Anomaly-based detection establishes a baseline of normal network behavior and generates alerts when deviations occur, making it effective against zero-day attacks, though it can suffer from higher false positive rates.