Attributes that characterize an attack are stored for reference using which of the following Intrusion Detection
System (IDS)?
A.
 signature-based IDS
B.
 statistical anomaly-based IDS
C.
 event-based IDS
D.
 inference-based IDS  
Explanation:
A signature based IDS monitors packets and compares them against a database of signatures or attributes
from known malicious threats.
Incorrect Answers:
B: An IDS which is anomaly based monitors network traffic and compares it against an established baseline,
which identifies what is “normal” for that network, and the alerts the relevant party when traffic is detected which
is significantly different to the baseline.
C, D: These are not valid IDS types.https://en.wikipedia.org/wiki/Intrusion_detection_system
https://en.wikipedia.org/wiki/Anomaly-based_intrusion_detection_system