NSE4 Security Profiles Practice Question
Which IPS detection method uses a baseline of normal traffic and alerts when deviations exceed a threshold?
⚠ Common exam trap
It's easy for candidates to confuse rate-based detection with anomaly detection, but rate-based detection uses fixed or adaptive thresholds on event counts (e.g., SYN flood rate) rather than a learned baseline of normal traffic behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly detection
Anomaly detection establishes a baseline of normal network traffic patterns and triggers alerts when observed traffic deviates significantly from that baseline. This method is effective for identifying unknown or zero-day attacks that do not match predefined signatures, as it relies on statistical or behavioral analysis rather than fixed patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anomaly detection
Why this is correct
Anomaly detection is the IPS technique that builds a statistical or machine-learning baseline of 'normal' network behavior by observing traffic patterns over time, including metrics like packet sizes, protocols, and session flows. Once the baseline is established, any significant deviation from that learned profile is flagged as an anomaly, potentially indicating a zero-day exploit or insider threat. This is the only method listed that fundamentally depends on a baseline of normal traffic to operate.
- ✗
Rate-based detection
Why it's wrong here
Rate-based detection does not rely on a general baseline of normal traffic; instead, it applies fixed or manually configured thresholds to specific traffic metrics such as connections per second, packets per second, or bytes per second. It triggers alarms when these measured rates exceed the preset limits, making it effective for high-volume flooding attacks like DDoS, but it does not adapt to each network's unique normal pattern. Thus, it uses preconfigured rate limits, not a learned profile of regular behavior.
- ✗
Signature-based detection
Why it's wrong here
Signature-based detection identifies threats by matching traffic against a database of predefined patterns, byte sequences, or regex rules that represent known attack payloads. It is highly accurate for known vulnerabilities and cannot flag new, unseen attacks because it lacks any understanding of what is normal for the network. This explicit reliance on pattern matching, rather than comparing traffic to a baseline of regular activity, clearly distinguishes it from anomaly-based approaches.
- ✗
Protocol decode-based detection
Why it's wrong here
Protocol decode-based detection inspects packets at the protocol layer, rigorously parsing headers and payloads to ensure compliance with RFC standards and protocol state machines. It can spot malformed packets, protocol violations, and ambiguous fields, such as overlapping TCP segments or out-of-band sequence numbers, that might evade signature checks. This approach does not establish a baseline of normal traffic; it validates conformance to protocol specifications, so it is fundamentally different from anomaly detection.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.