Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

Which IPS detection method uses a baseline of normal traffic and alerts when deviations exceed a threshold?

⚠ Common exam trap

It's easy for candidates to confuse rate-based detection with anomaly detection, but rate-based detection uses fixed or adaptive thresholds on event counts (e.g., SYN flood rate) rather than a learned baseline of normal traffic behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anomaly detection

Anomaly detection establishes a baseline of normal network traffic patterns and triggers alerts when observed traffic deviates significantly from that baseline. This method is effective for identifying unknown or zero-day attacks that do not match predefined signatures, as it relies on statistical or behavioral analysis rather than fixed patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Anomaly detection

    Why this is correct

    Anomaly detection is the IPS technique that builds a statistical or machine-learning baseline of 'normal' network behavior by observing traffic patterns over time, including metrics like packet sizes, protocols, and session flows. Once the baseline is established, any significant deviation from that learned profile is flagged as an anomaly, potentially indicating a zero-day exploit or insider threat. This is the only method listed that fundamentally depends on a baseline of normal traffic to operate.

  • ✗

    Rate-based detection

    Why it's wrong here

    Rate-based detection does not rely on a general baseline of normal traffic; instead, it applies fixed or manually configured thresholds to specific traffic metrics such as connections per second, packets per second, or bytes per second. It triggers alarms when these measured rates exceed the preset limits, making it effective for high-volume flooding attacks like DDoS, but it does not adapt to each network's unique normal pattern. Thus, it uses preconfigured rate limits, not a learned profile of regular behavior.

  • ✗

    Signature-based detection

    Why it's wrong here

    Signature-based detection identifies threats by matching traffic against a database of predefined patterns, byte sequences, or regex rules that represent known attack payloads. It is highly accurate for known vulnerabilities and cannot flag new, unseen attacks because it lacks any understanding of what is normal for the network. This explicit reliance on pattern matching, rather than comparing traffic to a baseline of regular activity, clearly distinguishes it from anomaly-based approaches.

  • ✗

    Protocol decode-based detection

    Why it's wrong here

    Protocol decode-based detection inspects packets at the protocol layer, rigorously parsing headers and payloads to ensure compliance with RFC standards and protocol state machines. It can spot malformed packets, protocol violations, and ambiguous fields, such as overlapping TCP segments or out-of-band sequence numbers, that might evade signature checks. This approach does not establish a baseline of normal traffic; it validates conformance to protocol specifications, so it is fundamentally different from anomaly detection.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.