Which detection method identifies threats by analyzing behavior patterns rather than known signatures?
- Signature-based
- Anomaly-based
- Heuristic
- All of these
Answer: Anomaly-based
Anomaly detection establishes baselines of normal behavior and flags deviations, enabling zero-day threat detection. Critical for advanced threat protection in modern SOCs.