Which technique analyzes network traffic patterns to detect anomalies without known signatures?
- Signature-based Detection
- Behavioral Analytics
- Heuristic Analysis
- Sandboxing
Answer: Behavioral Analytics
Behavioral Analytics uses ML to establish baselines of normal behavior and flag deviations indicating threats (insider threats, zero-days). Complements signature-based detection. Implemented in UEBA, NDR solutions. Critical for next-gen SOC and threat hunting questions.