Which four statements about Cisco IPS appliance anomaly detection histograms are true? (Choose four.)
A.
Histograms are learned or configured manually.
B.
Destination IP address row is the same for all histograms.
C.
Source IP address row can be learned or configured.
D.
Anomaly detection only builds a single histogram for all services in a zone.
E.
You can enable a separate histogram and scanner threshold for specific services, or use the default one for all other services.
F.
Anomaly detection histograms only track source (attacker) IP addresses.
Option A-B-C-E are correct.
I have the same idea. ABCE