NIST CSF Practice Question: What is baseline behavior in the context of anomaly detection? | CyberCertPrep
NISTNIST CSFDetect FunctionEASYFree question
What is baseline behavior in the context of anomaly detection?
A.The minimum security standard
B.The default system configuration
C.Normal patterns of network traffic, user activity, and system behavior used as a reference to identify deviations
D.The base security policy
Why C is correct
Baselines establish normal patterns of activity. Deviations from these baselines may indicate security incidents, policy violations, or system compromises.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Detect Function
NIST CSF Detect function: continuous monitoring, anomaly and event detection, and detection processes.
This question belongs to the "Detect" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Why is centralized log management important for detection?