Anomaly-based vs. Signature-based

in Security+
Can someone explain the differences in reference to detection. For whatever reason I am having one hell of a hard time getting these correct on practice tests.
Thanks,
- Chris
Thanks,
- Chris
WGU - Bachelors in Information Technology
“The liberty of speaking and writing guards our other liberties.” -- Thomas Jefferson
“The liberty of speaking and writing guards our other liberties.” -- Thomas Jefferson
Comments
It's just so hard to choose between the two in practice tests.
“The liberty of speaking and writing guards our other liberties.” -- Thomas Jefferson
Hope that helps.
Anomaly based is like many have stated base lining in order to detect some form of abnormality. I see Anomaly as like an organism that constantly changes or evolves having no identical pattern other than it not being the norm (baseline).
2023 Cert Goals: SC-100, eCPTX
I believe that anomaly based ids' are faster than signature based.
“The liberty of speaking and writing guards our other liberties.” -- Thomas Jefferson
Ouch. I guess someone didn't like my thoughts on this. Sorry.