Which AI Solution Checks If an IP Address Is Suspicious?

AI Security / Anomaly Detection

A company wants to use AI to protect its application from threats. The AI solution needs to check if an IP address is from a suspicious source. Which solution meets these requirements?

  1. Build a speech recognition system.
  2. Create a natural language processing (NLP) named entity recognition system.
  3. Develop an anomaly detection system. Source Reference Answer
  4. Create a fraud forecasting system.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to match AI use cases to the right technique: anomaly detection is designed to identify unusual patterns like suspicious IP addresses, and a common trap is confusing it with fraud forecasting.

For AI-powered threat detection, an anomaly detection system is the correct choice. This system learns normal traffic patterns and flags IP addresses that deviate from expected behavior, a point strongly supported by community consensus.

Option D, fraud forecasting, is the most likely wrong answer because it also deals with suspicious activity; however, it focuses on predicting future fraudulent transactions rather than identifying anomalies in IP address traffic.

Community Discussion (6 comments)

jove 👍 8 Selected: C
An anomaly detection system is designed to identify unusual patterns or behaviors within data
Udyan 👍 6
An anomaly detection system can analyze patterns and behaviors, such as IP address access patterns, to detect any deviations from the norm, which could indicate suspicious or malicious activity. An anomaly detection model can flag unusual access attempts, such as those from suspicious IP addresses, making it well-suited for threat detection. Fraud forecasting (option D) typically focuses on predicting potential fraud patterns rather than real-time anomaly detection, so it would not directly address the need to check IP addresses for suspicious activity. Thus, option C is the most suitable choice for identifying suspicious IP addresses in this scenario.
Jessiii 👍 1 Selected: C
Develop an anomaly detection system: Anomaly detection is a technique used to identify unusual patterns in data, such as suspicious IP addresses that deviate from normal behavior. By monitoring and analyzing network traffic, an anomaly detection system can flag IP addresses that exhibit abnormal behavior or characteristics that are indicative of potential threats. This is the most appropriate approach for identifying suspicious sources.
85b5b55 👍 1 Selected: C
Using Anomalies, patterns, and behaviours refers to identifying the event.
eesa 👍 1 Selected: C
Anomaly detection systema can be used to identify patterns that deviate from the norm. This makes them ideal for analyzing incoming IP addresses and flag suspicious IPs based on traffic patterns.
galliaj 👍 5
Anomaly detection systema can be used to identify patterns that deviate from the norm. This makes them ideal for analyzing incoming IP addresses and flag suspicious IPs based on traffic patterns.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An anomaly detection system is purpose-built to identify patterns that deviate from a learned norm. Community comment [2] explains that it can analyze IP address access patterns and flag deviations that indicate suspicious or malicious activity. Comment [3] reinforces this by stating that anomaly detection is ideal for analyzing incoming IP addresses and flagging suspicious IPs based on traffic patterns. This directly meets the requirement to check if an IP address is from a suspicious source.

Why the Other Options Are Wrong

Option A (speech recognition) converts spoken language into text and has no relation to IP address analysis. Option B (NLP named entity recognition) extracts entities like names or places from text, not network threat detection. Option D (fraud forecasting) is the closest distractor, but as comment [2] notes, it typically focuses on predicting fraudulent events like transactions, not on detecting unusual IP access patterns. Therefore, only option C aligns with the requirement.

Community Comment Notes

All commenters converge on answer C with no dissent. The highest-liked comment [1] states that anomaly detection systems are designed to identify unusual patterns or behaviors within data. Comments [2] and [4] add practical detail about monitoring network traffic and flagging abnormal IP behavior. This consensus reinforces that anomaly detection is the correct mapping for suspicious IP address detection in the AWS AI context.

Official Reference

Exam Strategy

Map the requirement to an AI use-case category: anomaly detection matches security/guardrail tasks. Eliminate options from unrelated domains—speech, NLP, or forecasting—and choose the technique that identifies deviations from normal behavior, not one that predicts future events.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide