Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) — Question 52

What is the difference between statistical detection and rule-based detection models?

Answer options

Correct answer: B

Explanation

The correct answer is B because it accurately describes that statistical detection focuses on establishing patterns of normal behavior over time, while rule-based detection operates on a specific IF/THEN criteria. Option A incorrectly describes rule-based detection's function, C does not pertain to the definitions provided, and D reverses the roles of statistical and rule-based detection.