問題文
An engineer notices that some intrusion events are labeled as informational and some severities include a suspicious level. Which option describes the two detection methods that produce those results?
選択肢
- One method matches the hashes of the files that arrive and the other blocks the sessions that stay open longer than the profile allows.
- One method matches the reputation of the files that arrive and the other flags the behavior that departs from the baseline.
- One method matches the hashes of known attacks and the other blocks the sessions that departs from the baseline.
- One method matches the patterns of attacks that are already known and the other flags the behavior that departs from the baseline.