Which Cisco IPS appliance feature is best used to detect these two conditions?
1) The network starts becoming congested by worm traffic.
2) A single worm-infected source enters the network and starts scanning for other vulnerable hosts.
A.
global correlation
B.
anomaly detection
C.
reputation filtering
D.
custom signature
E.
meta signature
F.
threat detection