SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security operations center (SOC) manager is evaluating a new intrusion detection system (IDS). The vendor claims the system can detect previously unknown attacks by building a baseline of normal network behavior and flagging deviations. Which detection methodology is the vendor describing?
⚠ Common exam trap
Candidates often confuse anomaly-based detection with heuristic or stateful protocol analysis, which do not rely on a learned baseline of normal network behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomaly-based detection
Anomaly-based detection is designed to identify unknown attacks by modeling normal behavior and detecting statistically significant deviations. This approach can catch zero-day exploits and insider threats that signature-based systems miss. However, it often generates false positives when legitimate but unusual activity occurs, requiring tuning. The vendor's claim of detecting previously unknown attacks through baseline deviation is a textbook description of anomaly-based detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Anomaly-based detection
Why this is correct
Anomaly-based detection establishes a baseline of normal activity and alerts on deviations from that baseline. This allows it to potentially identify zero-day or previously unknown attacks that do not match existing signatures. The vendor's description of building a baseline and flagging deviations aligns exactly with anomaly-based detection, making it the correct answer for this scenario.
- ✗
Stateful protocol analysis
Why it's wrong here
Stateful protocol analysis compares observed protocol behavior against predetermined profiles of benign activity for specific protocols. While it can detect deviations, it relies on vendor-developed protocol models rather than a custom baseline of the organization's normal traffic. The scenario emphasizes building a baseline of normal network behavior, which is more characteristic of anomaly-based detection than stateful protocol analysis.
- ✗
Signature-based detection
Why it's wrong here
Signature-based detection compares traffic against a database of known attack patterns. It cannot identify previously unknown attacks because no signature exists for them. While effective for known threats, it fails in this scenario where the vendor promises detection of novel attacks. Therefore, this methodology does not match the described capability of flagging deviations from a baseline.
- ✗
Heuristic-based detection
Why it's wrong here
Heuristic-based detection uses rules of thumb or algorithmic scoring to identify suspicious behavior, often in antivirus or email filtering. It does not necessarily build a dynamic baseline of normal network behavior for the environment. While heuristics can catch some unknown threats, the specific method of learning normal patterns and flagging deviations is anomaly-based detection, not heuristic analysis.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.